<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 14:20:05 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-12012</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-12012</link>
      <description>bdu:2026-12012</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-12012</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0299 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</link>
      <description>certfr-2026-avi-0299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0299</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-BB57522 — Security fixes in kubernetes-dns-node-cache 1.25.0-r8</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kubernetes-dns-node-cache&lt;/p&gt;
&lt;p&gt;Package kubernetes-dns-node-cache version 1.25.0-r8 fixes 17 vulnerabilities: CVE-2026-41178, CVE-2026-35579, CVE-2026-46600, CVE-2025-64702, CVE-2025-68151...&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: kubernetes-dns-node-cache&lt;/p&gt;
&lt;p&gt;Package kubernetes-dns-node-cache version 1.25.0-r8 fixes 17 vulnerabilities: CVE-2026-41178, CVE-2026-35579, CVE-2026-46600, CVE-2025-64702, CVE-2025-68151...&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-bb57522</guid>
    </item>
    <item>
      <title>EUVD-2026-337446</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337446</link>
      <description>EUVD-2026-337446</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337446</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26018</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26018</link>
      <description>&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS&amp;#39;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS&amp;#39;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26018</guid>
    </item>
    <item>
      <title>GHSA-h75p-j8xm-m278 — CoreDNS Loop Detection Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h75p-j8xm-m278</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/coredns/coredns&lt;/p&gt;
&lt;p&gt;## Executive Summary&lt;/p&gt;
&lt;p&gt;A Denial of Service vulnerability exists in CoreDNS&amp;#39;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process.&lt;/p&gt;
&lt;p&gt;---
## Technical Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Description&lt;/p&gt;
&lt;p&gt;The CoreDNS `loop` plugin is designed to detect forwarding loops by performing a self-test during server startup. The plugin generates a random query name (`qname`) using Go&amp;#39;s `math/rand` package and sends an HINFO query to itself. If the server receives multiple matching queries, it assumes a forwarding loop exists and terminates.&lt;/p&gt;
&lt;p&gt;**The vulnerability arises from two design flaws:**&lt;/p&gt;
&lt;p&gt;1. **Predictable PRNG Seed**: The random number generator is seeded with `time.Now().UnixNano()`, making the generated qname predictable if an attacker knows the approximate server start time.&lt;/p&gt;
&lt;p&gt;2. **Fatal Error Handler**: When the plugin detects what it believes is a loop (3+ matching HINFO queries), it calls `log.Fatalf()` which invokes `os.Exit(1)`, immediately terminating the process without cleanup or recovery.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;**File: `plugin/loop/setup.go`**
```go
// PRNG seeded with predictable timestamp
var r = rand.New(time.Now().UnixNano())&lt;/p&gt;
&lt;p&gt;// Qname generation using two consecutive PRNG calls
func qname(zone string) string {
    l1 := strconv.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/coredns/coredns&lt;/p&gt;
&lt;p&gt;## Executive Summary&lt;/p&gt;
&lt;p&gt;A Denial of Service vulnerability exists in CoreDNS&amp;#39;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process.&lt;/p&gt;
&lt;p&gt;---
## Technical Details&lt;/p&gt;
&lt;p&gt;### Vulnerability Description&lt;/p&gt;
&lt;p&gt;The CoreDNS `loop` plugin is designed to detect forwarding loops by performing a self-test during server startup. The plugin generates a random query name (`qname`) using Go&amp;#39;s `math/rand` package and sends an HINFO query to itself. If the server receives multiple matching queries, it assumes a forwarding loop exists and terminates.&lt;/p&gt;
&lt;p&gt;**The vulnerability arises from two design flaws:**&lt;/p&gt;
&lt;p&gt;1. **Predictable PRNG Seed**: The random number generator is seeded with `time.Now().UnixNano()`, making the generated qname predictable if an attacker knows the approximate server start time.&lt;/p&gt;
&lt;p&gt;2. **Fatal Error Handler**: When the plugin detects what it believes is a loop (3+ matching HINFO queries), it calls `log.Fatalf()` which invokes `os.Exit(1)`, immediately terminating the process without cleanup or recovery.&lt;/p&gt;
&lt;p&gt;### Affected Code&lt;/p&gt;
&lt;p&gt;**File: `plugin/loop/setup.go`**
```go
// PRNG seeded with predictable timestamp
var r = rand.New(time.Now().UnixNano())&lt;/p&gt;
&lt;p&gt;// Qname generation using two consecutive PRNG calls
func qname(zone string) string {
    l1 := strconv.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h75p-j8xm-m278</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-26018</link>
      <description>msrc_CVE-2026-26018</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-26018</guid>
    </item>
    <item>
      <title>OESA-2026-3184 — coredns security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3184</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: coredns, openEuler:20.03-LTS-SP4: coredns, openEuler:22.03-LTS-SP4: coredns, openEuler:24.03-LTS-SP1: coredns, openEuler:24.03-LTS-SP3: coredns&lt;/p&gt;
&lt;p&gt;CoreDNS is a fast and flexible DNS server. The key word here is flexible: with CoreDNS you are able to do what you want with your DNS data by utilizing plugins.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS&amp;amp;apos;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.(CVE-2026-26018)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: coredns, openEuler:20.03-LTS-SP4: coredns, openEuler:22.03-LTS-SP4: coredns, openEuler:24.03-LTS-SP1: coredns, openEuler:24.03-LTS-SP3: coredns&lt;/p&gt;
&lt;p&gt;CoreDNS is a fast and flexible DNS server. The key word here is flexible: with CoreDNS you are able to do what you want with your DNS data by utilizing plugins.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS&amp;amp;apos;s loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.(CVE-2026-26018)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3184</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10297-1 — coredns-1.14.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10297-1</link>
      <description>&lt;p&gt;coredns-1.14.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;coredns-1.14.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10297-1</guid>
    </item>
    <item>
      <title>RHSA-2026:25127 — Red Hat Security Advisory: Submariner v0.21 security fixes and container updates</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:25127</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) net/url: Incorrect parsing of IPv6 host literals in net/url github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/coredns/coredns: CoreDNS: Denial of Service via oversized DNS-over-HTTPS GET requests google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object github.com/coredns/coredns: CoreDNS: Authentication bypass allows unauthorized access to TSIG-protected functionalities&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation golang: net/url: Memory exhaustion in query parameter parsing in net/url golang: archive/zip: Excessive CPU consumption when building archive index in archive/zip crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption github.com/coredns/coredns/core/dnsserver: CoreDNS DoS via unbounded connections and oversized messages urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) net/url: Incorrect parsing of IPv6 host literals in net/url github.com/coredns/coredns: CoreDNS: DNS access control bypass due to plugin execution order flaw github.com/coredns/coredns: CoreDNS: Denial of Service vulnerability due to predictable pseudo-random number generation crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building github.com/coredns/coredns: CoreDNS: Denial of Service via oversized DNS-over-HTTPS GET requests google.golang.org/grpc/grpc-go: google.golang.org/grpc/authz: gRPC-Go: Authorization bypass due to improper HTTP/2 path validation github.com/go-jose/go-jose/v3: github.com/go-jose/go-jose/v4: Go JOSE: Denial of Service via crafted JSON Web Encryption (JWE) object github.com/coredns/coredns: CoreDNS: Authentication bypass allows unauthorized access to TSIG-protected functionalities&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:25127</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0627 — CoreDNS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0627</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CoreDNS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CoreDNS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, und um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0627</guid>
    </item>
  </channel>
</rss>
