Affected by GO-2026-4630
and 6 other vulnerabilities
GO-2026-4630 : CoreDNS ACL Bypass in github.com/coredns/coredns
GO-2026-4635 : CoreDNS Loop Detection Denial of Service Vulnerability in github.com/coredns/coredns
GO-2026-4969 : CoreDNS' DoQ worker pool does not bound stream backlog in github.com/coredns/coredns
GO-2026-5164 : CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification in github.com/coredns/coredns
GO-2026-5417 : CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass) in github.com/coredns/coredns
GO-2026-5583 : CoreDNS has TSIG authentication bypass on DoT, DoH, DoH3, DoQ, and gRPC in github.com/coredns/coredns
GO-2026-5667 : CoreDNS has TSIG authentication bypass on gRPC and QUIC transports in github.com/coredns/coredns
Discover Packages
github.com/coredns/coredns
plugin
deprecated
package
Version:
v1.14.0
Opens a new window with list of versions in this module.
Published: Jan 7, 2026
License: Apache-2.0
Opens a new window with license information.
Imports: 3
Opens a new window with list of imports.
Imported by: 5
Opens a new window with list of known importers.
Documentation
Documentation
¶
Package deprecated is used when we deprecated plugin. In plugin.cfg just go from
startup:github.com/coredns/caddy/startupshutdown
To:
startup:deprecated
And things should work as expected. This means starting CoreDNS will fail with an error. We can only
point to the release notes to details what next steps a user should take. I.e. there is no way to add this
to the error generated.
Source Files
¶
Click to show internal directories.
Click to hide internal directories.