PT-2026-35876 · Coredns+1 · Coredns+1

·

CVE-2026-33190

·

Published

2026-04-28

·

Updated

2026-07-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.3
Description The tsig plugin can be bypassed on non-plain-DNS transports, specifically DoT, DoH, DoH3, DoQ, and gRPC. This occurs because the plugin relies on the transport writer's TsigStatus() function instead of performing its own verification. Specifically, the TsigStatus() function for DoH, DoH3, DoQ, and gRPC writers unconditionally returns nil, and the DoT server fails to set TsigSecret on the dns.Server. This flaw allows an unauthenticated remote client to bypass TSIG-based authentication and access resources restricted by a tsig require all policy, such as privileged queries or zone data. Plain DNS over TCP and UDP are not affected.
Recommendations Update CoreDNS to version 1.14.3 or later.

Exploit

Fix

DoS

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SL86558
CLEANSTART-2026-VJ54611
CVE-2026-33190
GHSA-QHMP-Q7XH-99RH
GO-2026-5583
OPENSUSE-SU-2026:10673-1
OPENSUSE-SU-2026:20703-1
OPENSUSE-SU-2026:21483-1

Affected Products

Coredns
Red Os