Unintended Proxy or Intermediary in CoreDNS - CVE-2026-86003
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify DNS records.
The vulnerability exists due to an unintended proxy or intermediary behavior in the DoH, DoH3, DoQ, and DNS-over-gRPC listeners when processing RFC 2136 UPDATE messages. A remote attacker can send an unsigned RFC 2136 UPDATE message to modify DNS records.
Exploitation requires an update-capable upstream target that trusts CoreDNS's source address or connection and does not require an attacker-unknown TSIG.
Affected software
openEuler
coredns
coredns-help
How to mitigate CVE-2026-86003
coredns - addressed in versions 1.7.0-1.10, 1.7.0-1.11
coredns-help - addressed in versions 1.7.0-1.10, 1.7.0-1.11