THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9gm5-9rfh-m6vx (high) — CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

[GHSA] GHSA-9gm5-9rfh-m6vx (high) — CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

highgithub_advisoriesPublished 2026-09-17

GHSA-9gm5-9rfh-m6vx Severity: high CVE: CVE-2026-86003

CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP

### Summary

CoreDNS accepted RFC 2136 UPDATE messages over DoH, DoH3, DoQ, and DNS-over-gRPC, then allowed the `proxy`/`forward` plugin to send them unchanged to an upstream DNS server. UDP, TCP, and DoT rejected the same opcode

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9gm5-9rfh-m6vx