CVE-2026-26018
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 1.12%
- CWE
- CWE-337, CWE-770, CWE-400
- Published
- 2026-03-06
- Last modified
- 2026-07-15
Affected products
- coredns coredns
Weakness type
Related vulnerabilities
- CVE-2026-25235 — PEAR Has a Predictable Verification Hash in Election Account Requests
- CVE-2025-62710 — Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
- CVE-2025-55069 — AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator
- CVE-2025-20613 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may...
- CVE-2025-7770 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
- CVE-2024-7558 — JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju...
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code
- CVE-2023-49343 — Temporary data passed between application components by Budgie Extras Dropby applet could...