CVE-2026-26018CWE-337CWE-400CWE-770

CoreDNS Loop Detection Denial of Service Vulnerability

High · published March 6, 2026

CVSS v3.1
7.5
EPSS
1%
Percentile
63.9
In the wild
Unconfirmed
What it is

CoreDNS is a DNS server that chains plugins. Prior to version 1.14.2, a denial of service vulnerability exists in CoreDNS's loop detection plugin that allows an attacker to crash the DNS server by sending specially crafted DNS queries. The vulnerability stems from the use of a predictable pseudo-random number generator (PRNG) for generating a secret query name, combined with a fatal error handler that terminates the entire process. This issue has been patched in version 1.14.2.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
Not supplied
EPSS
0.01116 · 63.9th percentile
Weaknesses
CWE-337 · Predictable Seed in Pseudo-Random Number Generator (PRNG); CWE-400 · Uncontrolled Resource Consumption; CWE-770 · Allocation of Resources Without Limits or Throttling
Published
2026-03-06T15:35Z
EPSS history
Timeline
  • 06 MAR 15:35Z
    CoreDNS Loop Detection Denial of Service Vulnerability
    cvelistv5