<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:32:46 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12011</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12011</link>
      <description>bdu:2026-12011</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12011</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0299 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</link>
      <description>certfr-2026-avi-0299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BB57522 — Security fixes in kubernetes-dns-node-cache 1.25.0-r8</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kubernetes-dns-node-cache&lt;/p&gt;
&lt;p&gt;Package kubernetes-dns-node-cache version 1.25.0-r8 fixes 17 vulnerabilities: CVE-2026-41178, CVE-2026-35579, CVE-2026-46600, CVE-2025-64702, CVE-2025-68151...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kubernetes-dns-node-cache&lt;/p&gt;
&lt;p&gt;Package kubernetes-dns-node-cache version 1.25.0-r8 fixes 17 vulnerabilities: CVE-2026-41178, CVE-2026-35579, CVE-2026-46600, CVE-2025-64702, CVE-2025-68151...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522</guid>
    </item>
    <item>
      <title>EUVD-2026-337447</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337447</link>
      <description>EUVD-2026-337447</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337447</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26017</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26017</link>
      <description>&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26017</guid>
    </item>
    <item>
      <title>GHSA-c9v3-4pv7-87pr — CoreDNS ACL Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c9v3-4pv7-87pr</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/coredns/coredns&lt;/p&gt;
&lt;p&gt;A logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In multi-tenant Kubernetes clusters, this flaw undermines DNS-based segmentation strategies.&lt;/p&gt;
&lt;p&gt;Example scenario:
1. ACL blocks access to *.admin.svc.cluster.local
2. A rewrite rule maps public-name → admin.svc.cluster.local
3. An unprivileged pod queries public-name
4. ACL allows the request
5. Rewrite exposes the internal admin service IP&lt;/p&gt;
&lt;p&gt;This allows unauthorized service discovery and reconnaissance of restricted internal infrastructure.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;- Reorder the default plugin.cfg so that:
   - rewrite and other normalization plugins run before acl, opa, and firewall
- Ensure all access control checks are applied after name normalization.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/coredns/coredns&lt;/p&gt;
&lt;p&gt;A logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;In multi-tenant Kubernetes clusters, this flaw undermines DNS-based segmentation strategies.&lt;/p&gt;
&lt;p&gt;Example scenario:
1. ACL blocks access to *.admin.svc.cluster.local
2. A rewrite rule maps public-name → admin.svc.cluster.local
3. An unprivileged pod queries public-name
4. ACL allows the request
5. Rewrite exposes the internal admin service IP&lt;/p&gt;
&lt;p&gt;This allows unauthorized service discovery and reconnaissance of restricted internal infrastructure.&lt;/p&gt;
&lt;p&gt;### Patches
_Has the problem been patched? What versions should users upgrade to?_&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;- Reorder the default plugin.cfg so that:
   - rewrite and other normalization plugins run before acl, opa, and firewall
- Ensure all access control checks are applied after name normalization.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c9v3-4pv7-87pr</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-26017 — CoreDNS ACL Bypass</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-26017</link>
      <description>msrc_CVE-2026-26017</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-26017</guid>
    </item>
    <item>
      <title>OESA-2026-2939 — coredns security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-2939</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: coredns&lt;/p&gt;
&lt;p&gt;CoreDNS is a fast and flexible DNS server. The key word here is flexible: with CoreDNS you are able to do what you want with your DNS data by utilizing plugins.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.(CVE-2026-26017)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: coredns&lt;/p&gt;
&lt;p&gt;CoreDNS is a fast and flexible DNS server. The key word here is flexible: with CoreDNS you are able to do what you want with your DNS data by utilizing plugins.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.(CVE-2026-26017)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-2939</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10297-1 — coredns-1.14.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10297-1</link>
      <description>&lt;p&gt;coredns-1.14.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;coredns-1.14.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10297-1</guid>
    </item>
    <item>
      <title>RHSA-2026:25127 — Red Hat Security Advisory: Submariner v0.21 security fixes and container updates</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25127</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) net/url: Incorrect parsing of IPv6 host literals in net/url github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/coredns/coredns: CoreDNS: Denial of Service via oversized DNS-over-HTTPS GET requests google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object github.com/coredns/coredns: CoreDNS: Authentication bypass allows unauthorized access to TSIG-protected functionalities&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) net/url: Incorrect parsing of IPv6 host literals in net/url github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/coredns/coredns: CoreDNS: Denial of Service via oversized DNS-over-HTTPS GET requests google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object github.com/coredns/coredns: CoreDNS: Authentication bypass allows unauthorized access to TSIG-protected functionalities&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25127</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0627 — CoreDNS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0627</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CoreDNS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CoreDNS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0627</guid>
    </item>
  </channel>
</rss>
