High severity7.5NVD Advisory· Published Jul 16, 2026· Updated Jul 22, 2026
CVE-2026-62309
CVE-2026-62309
Description
CoreDNS is a DNS server written in Go. Prior to 1.14.4, a single 28-byte UDP datagram can crash the CoreDNS process when the proxyproto plugin is enabled because plugin/pkg/proxyproto/proxyproto.go PacketConn.ReadFrom handles a PROXY v2 header with non-UDP transport such as family byte 0x11, reassigns addr from a nil readFrom result after parseProxyProtocol errors, and calls addr.String() in the warning log before ServeDNS recovery applies. This issue is fixed in version 1.14.4.
Affected products
2Patches
Vulnerability mechanics
References
4- github.com/coredns/coredns/commit/60a439dd4febfcd78e3779e952fe3fbf3c16bb1fnvdPatch
- github.com/coredns/coredns/pull/8154nvdIssue TrackingPatch
- github.com/coredns/coredns/security/advisories/GHSA-9rvv-m5g5-wc8rnvdExploitThird Party Advisory
- github.com/coredns/coredns/releases/tag/v1.14.4nvdRelease Notes
News mentions
0No linked articles in our index yet.