Cluster add-ons

CoreDNS: what changed

In the last 90 days, 3 summarized changes: 1 security advisories, 1 releases, 1 fixes. Stackdiff reads CoreDNS's own feeds (github.com) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

1.14.7Securitymedium
v1.14.7

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

News
Recursion into madness
News
Cores in space: The core memory module from a 1980 Spacelab computer
News
Omarchy: Any User Process Can Escalate to Root
1.14.7Securitymedium
v1.14.7
1.14.6Fix
v1.14.6
1.14.5Release
v1.14.5
1.14.4Release
v1.14.4
1.14.3Securitymedium
GHSA-vp29-5652-4fw9: CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
1.14.3Securitymedium
GHSA-qhmp-q7xh-99rh: CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC
1.14.3Securitymedium
GHSA-h8mm-c463-wjq3: CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
1.14.3Securityhigh
GHSA-63cw-r7xf-jmwr: CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
1.14.3Securityhigh
GHSA-2wpx-qpw2-g5h5: CoreDNS' DoQ worker pool does not bound stream backlog
1.14.3Securitymedium
v1.14.3
1.14.2Securitymedium
GHSA-h75p-j8xm-m278: CoreDNS Loop Detection Denial of Service Vulnerability
1.14.2Securitymedium
GHSA-c9v3-4pv7-87pr: CoreDNS ACL Bypass
1.14.2Securitymedium
v1.14.2
1.14.1Securitymedium
v1.14.1
1.14.0Securitycritical
GHSA-527x-5wrf-22m2: CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
1.14.0Securitymedium
v1.14.0
1.13.2Deprecatedmedium
v1.13.2
1.13.1Fix
v1.13.1
1.12.4Securitymedium
GHSA-93mf-426m-g6x9: CoreDNS: DNS Cache Pinning via etcd Lease ID Confusion
1.12.2Securityhigh
GHSA-cvx7-x8pj-x2gw: CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
Securitymedium
GHSA-h92q-fgpp-qhrq: CoreDNS Cache Poisoning via a birthday attack
1.11.0Securityhigh
GHSA-hfmw-7g3m-gj6q: CoreDNS vulnerable to TuDoor Attacks
1.11.2Securitymedium
GHSA-m9w6-wp3h-vq8g: CoreDNS may return invalid cache entries
Securitymedium
GHSA-h828-v5pv-33qx: coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
Securitymedium
GHSA-ch7v-37xg-75ph: coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
1.6.6Securitymedium
GHSA-gv9j-4w24-q7vx: Improper random number generation in github.com/coredns/coredns

Where Stackdiff reads CoreDNS

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get CoreDNS changes in your Monday brief

Add CoreDNS and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other cluster add-ons tools