Affected by GO-2026-4289
and 7 other vulnerabilities
GO-2026-4289: CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages in github.com/coredns/coredns
GO-2026-4630: CoreDNS ACL Bypass in github.com/coredns/coredns
GO-2026-4635: CoreDNS Loop Detection Denial of Service Vulnerability in github.com/coredns/coredns
GO-2026-4969: CoreDNS' DoQ worker pool does not bound stream backlog in github.com/coredns/coredns
GO-2026-5164: CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification in github.com/coredns/coredns
GO-2026-5417: CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass) in github.com/coredns/coredns
GO-2026-5583: CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC in github.com/coredns/coredns
GO-2026-5667: CoreDNS has TSIG authentication bypass on gRPC and QUIC transports in github.com/coredns/coredns
NewDurationFromArg returns a time.Duration from a configuration argument
(string) which has come from the Corefile. The argument has some basic
validation applied before returning a time.Duration. If the argument has no
time unit specified and is numeric the argument will be treated as seconds
rather than GO's default of nanoseconds.