{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acoredns.iocoredns/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":3.7,"id":"CVE-2026-62994"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CoreDNS"],"_cs_severities":["low"],"_cs_tags":["coredns","denial-of-service","kubernetes","cve"],"_cs_type":"advisory","_cs_vendors":["CoreDNS"],"content_html":"\u003cp\u003eCVE-2026-62994 details a denial-of-service vulnerability affecting CoreDNS, a widely used DNS server for Kubernetes environments. The vulnerability resides within the \u003ccode\u003ek8s_external\u003c/code\u003e plugin, specifically when handling authoritative zone transfer (AXFR) requests in a headless configuration. Under certain conditions, this plugin can incorrectly generate and emit an empty transfer batch to the \u003ccode\u003etransfer\u003c/code\u003e plugin. The \u003ccode\u003etransfer\u003c/code\u003e plugin, upon receiving this unexpected empty batch, enters a panic state, causing the CoreDNS process to crash. This can lead to service disruption for critical DNS resolution within Kubernetes clusters and other environments relying on CoreDNS. While the advisory does not specify observed exploitation, the nature of a DNS server crash makes it a high-impact issue for availability and reliability. The specific conditions under which the \u003ccode\u003ek8s_external\u003c/code\u003e plugin emits an empty batch are not fully detailed but relate to specific configurations or data states during an AXFR.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker or malformed client initiates an authoritative zone transfer (AXFR) request targeting a vulnerable CoreDNS server configured with the \u003ccode\u003ek8s_external\u003c/code\u003e plugin.\u003c/li\u003e\n\u003cli\u003eThe CoreDNS server receives the AXFR query for a zone that it is authoritative for and is handled by the \u003ccode\u003ek8s_external\u003c/code\u003e plugin.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ek8s_external\u003c/code\u003e plugin, operating in a headless configuration, processes the incoming AXFR request.\u003c/li\u003e\n\u003cli\u003eDue to an internal logic flaw or specific data conditions, the \u003ccode\u003ek8s_external\u003c/code\u003e plugin attempts to emit an empty transfer batch in response to the AXFR request.\u003c/li\u003e\n\u003cli\u003eThis empty transfer batch is then passed to the CoreDNS \u003ccode\u003etransfer\u003c/code\u003e plugin for further processing.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003etransfer\u003c/code\u003e plugin encounters an unhandled exception or null pointer dereference when attempting to process the unexpected empty transfer batch.\u003c/li\u003e\n\u003cli\u003eThis unhandled exception triggers a panic within the CoreDNS process, leading to an immediate crash of the server.\u003c/li\u003e\n\u003cli\u003eThe CoreDNS server becomes unavailable, resulting in a denial of service for DNS resolution requests until the process is restarted.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-62994 results in a denial of service for the affected CoreDNS server. In Kubernetes environments, this can severely disrupt container networking, service discovery, and external communication, leading to widespread application outages and loss of functionality for all services relying on CoreDNS for name resolution. For other deployments, a crashed CoreDNS instance means DNS resolution failures, making network services unreachable. The impact scales with the criticality of the services relying on the affected DNS server. While the advisory does not specify observed exploitation or targeted sectors, any organization using vulnerable CoreDNS deployments is at risk of significant operational downtime.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-62994 by updating CoreDNS to a version that addresses this vulnerability immediately, as indicated by the Microsoft Security Response Center reference.\u003c/li\u003e\n\u003cli\u003eMonitor CoreDNS server logs for sudden, unexpected process terminations or restarts which could indicate a denial-of-service event related to CVE-2026-62994.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T07:35:22Z","date_published":"2026-07-23T07:35:22Z","id":"https://feed.craftedsignal.io/briefs/2026-07-coredns-dos-cve-2026-62994/","summary":"A vulnerability in CoreDNS, specifically within the `k8s_external` plugin, allows for a denial of service when performing a headless AXFR, as the `k8s_external` plugin can emit an empty transfer batch, which subsequently causes the `transfer` plugin to panic.","title":"CoreDNS CVE-2026-62994 Denial of Service Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-coredns-dos-cve-2026-62994/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}