A remote, anonymous attacker can exploit a vulnerability in CoreDNS to cause a Denial of Service attack. The vulnerability has a CVSS base score of 7.5 (High) and affects open-source CoreDNS versions prior to 1.12.2. The advisory indicates a mitigation is available, but a specific fixed version or detailed workaround is not provided in this summary.
[WID-SEC-2025-1261] CoreDNS: Schwachstelle ermöglicht Denial of Service CVSS Base Score 7.5 (hoch) CVSS Temporal Score 6.5 (mittel) Remoteangriff ja Datum 09.06.2025 Stand UPDATE 09.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux UNIX Produktbeschreibung CoreDNS ist ein DNS server. Produkte UPDATE 20.11.2025 Red Hat Enterprise Linux 09.06.2025 Open Source CoreDNS <1.12.2 Angriff Angriff Ein entfernter, anonymer Angreifer kann eine Schwachstelle in CoreDNS ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben