An open index of dependabot pull requests across open source projects.

github.com/coredns/coredns

Ecosystem:
go
Package URL:
pkg:golang/github.com/coredns/coredns
Total PRs:
149 Dependabot PRs
Latest PR:
about 2 months ago
Unique Repositories:
57 repositories
Unique Repos (30 days):
2 repositories
Security Advisories
CoreDNS has TSIG authentication bypass on gRPC and QUIC transports
GHSA-vp29-5652-4fw9 CVE-2026-35579 HIGH published about 2 months ago • updated 8 days ago
### Summary The gRPC, QUIC, DoH, and DoH3 transports in CoreDNS incorrectly handle TSIG authentication. For gRPC and QUIC, CoreDNS checks whether...
Improper random number generation in github.com/coredns/coredns
GHSA-gv9j-4w24-q7vx MODERATE published over 4 years ago • updated 1 day ago
### Impact CoreDNS before 1.6.6 (using go DNS package < 1.1.25) improperly generates random numbers because math/rand is used. The TXID becomes pr...
CoreDNS Cache Poisoning via a birthday attack
GHSA-h92q-fgpp-qhrq CVE-2023-30464 MODERATE published over 1 year ago • updated 8 days ago
CoreDNS through 1.10.1 enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.
CoreDNS vulnerable to TuDoor Attacks
GHSA-hfmw-7g3m-gj6q CVE-2023-28452 HIGH published over 1 year ago • updated 8 days ago
An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid re...
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
GHSA-ch7v-37xg-75ph CVE-2022-2835 MODERATE published over 3 years ago • updated about 9 hours ago
A flaw was found in coreDNS. This flaw allows a malicious user to reroute internal calls to some internal services that were accessed by the FQDN i...
Recent PRs
Package Details
Name: github.com/coredns/coredns
Ecosystem: go
PURL Type: golang
Package URL: pkg:golang/github.com/coredns/coredns
JSON API: View JSON
Security Advisories

16

Active advisories
HIGH 10
MODERATE 6
View All golang Advisories
Package Information
Description:

Repository: https://github.com/coredns/coredns
Homepage: https://github.com/coredns/coredns
Latest Release: v1.12.2
about 1 year ago
Dependent Repos: 1,324
Dependent Packages: 4,631
Ranking: Top 0.2159% by dependent repos Top 0.0425% by dependent pkgs
PR Status
Open 73 (49.0%)
Merged 20 (13.4%)
Closed 45 (30.2%)
PR Types
Minor 56 (37.6%)
Patch 79 (53.0%)