{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-82399/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:coredns:coredns:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-86003"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CoreDNS (\u003c= 1.14.6)"],"_cs_severities":["high"],"_cs_tags":["dns","coredns","vulnerability","rfc-2136","denial-of-service","cve-2026-82399","networking"],"_cs_type":"advisory","_cs_vendors":["CoreDNS"],"content_html":"\u003cp\u003eCoreDNS versions 1.14.6 and earlier contain a vulnerability where DNS-over-HTTPS (DoH), DNS-over-HTTPS3 (DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC listeners do not enforce the same request policy applied to standard UDP and TCP listeners. Specifically, these modern transports failed to filter out RFC 2136 UPDATE messages. When CoreDNS is configured with the 'forward' or 'proxy' plugin, it forwards these unauthorized UPDATE messages to an upstream authoritative DNS server.\u003c/p\u003e\n\u003cp\u003eIf the upstream server is configured to trust requests originating from the CoreDNS server IP address or an authenticated session, the upstream will process these updates as legitimate requests from the proxy itself. This bypasses the need for the attacker to provide end-to-end TSIG authentication, enabling unauthorized modification, redirection, or deletion of DNS records in the target zone. Defenders should patch CoreDNS to the latest version to ensure UPDATE opcodes are rejected by these transports before plugin dispatch.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a CoreDNS instance reachable via DoH, DoH3, DoQ, or gRPC.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an RFC 2136 UPDATE packet targeting a zone hosted by an upstream DNS server configured behind the CoreDNS instance.\u003c/li\u003e\n\u003cli\u003eAttacker sends the malicious UPDATE packet to the target CoreDNS instance over one of the vulnerable transports (e.g., DoH).\u003c/li\u003e\n\u003cli\u003eThe CoreDNS listener parses the message header without invoking \u003ccode\u003edns.DefaultMsgAcceptFunc\u003c/code\u003e to validate the opcode.\u003c/li\u003e\n\u003cli\u003eThe CoreDNS server dispatches the unauthorized UPDATE message to the 'forward' or 'proxy' plugin.\u003c/li\u003e\n\u003cli\u003eThe 'forward' plugin encapsulates or relays the original UPDATE request to the upstream authoritative server.\u003c/li\u003e\n\u003cli\u003eThe upstream server accepts the UPDATE, trusting the request due to the established connection or trusted source IP of the CoreDNS server.\u003c/li\u003e\n\u003cli\u003eThe upstream server modifies the DNS record, leading to traffic redirection or zone disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to manipulate DNS infrastructure. By injecting or altering records, attackers can facilitate traffic redirection (man-in-the-middle), intercept sensitive data, disrupt mail delivery, or take over legitimate names. The scope of impact depends on the sensitivity of the zones managed by the upstream authoritative servers and whether they rely on the CoreDNS proxy for implicit trust.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of CoreDNS to a version containing the fix for CVE-2026-86003.\u003c/li\u003e\n\u003cli\u003eAudit CoreDNS 'forward' and 'proxy' plugin configurations to ensure upstream servers require explicit TSIG authentication for all zones that accept dynamic updates.\u003c/li\u003e\n\u003cli\u003eMonitor logs for unusual DNS UPDATE activity originating from CoreDNS infrastructure toward sensitive internal or external authoritative zones.\u003c/li\u003e\n\u003cli\u003eRestrict access to DoH, DoQ, and gRPC endpoints to authorized clients at the network edge if these services are not required for public exposure.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T01:11:37Z","date_published":"2026-09-18T01:11:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-coredns-dns-update-bypass/","summary":"CoreDNS versions up to 1.14.6 fail to validate DNS UPDATE opcodes over DoH, DoH3, DoQ, and gRPC, allowing attackers to relay unauthorized updates to upstream servers.","title":"CoreDNS DoH/DoQ/gRPC RFC 2136 UPDATE Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-coredns-dns-update-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-82399","version":"https://jsonfeed.org/version/1.1"}