REDHAT-BUG-2445244: High severity CoreDNS CoreDNS vulnerability

Published Mar 6, 2026
·
Updated

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a logical vulnerability in CoreDNS allows DNS access controls to be bypassed due to the default execution order of plugins. Security plugins such as acl are evaluated before the rewrite plugin, resulting in a Time-of-Check Time-of-Use (TOCTOU) flaw. This issue has been patched in version 1.14.2.

Affected Software

1 affected component
CoreDNS CoreDNS<1.14.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade CoreDNS to a version that resolves this vulnerability.

    Fixed in 1.14.2

Event History

Mar 6, 2026
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2445244?

The severity of REDHAT-BUG-2445244 is classified as high with a score of 7.

2

How do I fix REDHAT-BUG-2445244?

To fix REDHAT-BUG-2445244, upgrade CoreDNS to version 1.14.2 or later.

3

What vulnerability exists in CoreDNS related to REDHAT-BUG-2445244?

REDHAT-BUG-2445244 describes a logical vulnerability that allows DNS access control to be bypassed due to the execution order of plugins.

4

Which plugins are affected by the vulnerability in REDHAT-BUG-2445244?

The acl security plugin and the rewrite plugin are directly affected by the vulnerability identified in REDHAT-BUG-2445244.

5

What impact could REDHAT-BUG-2445244 have on my network?

If exploited, REDHAT-BUG-2445244 could allow unauthorized DNS queries and control over DNS access, compromising network security.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203