FlawAtlas
Search the atlas
CVE-2023-28452 High

CoreDNS vulnerable to TuDoor Attacks in github.com/coredns/coredns

CoreDNS vulnerable to TuDoor Attacks in github.com/coredns/coredns

Exploit probability 0.6%
Published September 25, 2024
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

64 explicit affected versions

Go github.com/coredns/coredns
Go github.com/coredns/coredns

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-28452

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.

View original source
Open Source Vulnerabilities GHSA-hfmw-7g3m-gj6q

An issue was discovered in CoreDNS through 1.10.1. There is a vulnerability in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing denial of service for normal resolution. In an exploit, the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.

View original source
Open Source Vulnerabilities GO-2024-3130

CoreDNS vulnerable to TuDoor Attacks in github.com/coredns/coredns

View original source

05 / REFERENCES

Further evidence