NULL pointer dereference in CoreDNS - CVE-2026-62299
Published: July 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a null pointer dereference in the rewrite plugin edns0 response-revert rules when processing a downstream response with no OPT record after a matching edns0 rewrite rule with the revert flag enabled. A remote attacker can send a DNS query that triggers the queued response rule to cause a denial of service.
If the debug directive is enabled, the panic is not recovered and the issue can crash the entire CoreDNS process.