{"id":"AZL-92895","summary":"CVE-2026-62994 affecting package coredns for versions less than 1.11.4-20","details":"CoreDNS is a DNS server written in Go. From 1.9.4 until 1.14.5, a network DNS client allowed to request AXFR for a CoreDNS zone can trigger a panic when CoreDNS is configured with k8s_external headless-service zone transfers and Kubernetes contains a headless service endpoint with no declared ports; plugin/kubernetes/object/endpoint.go creates Port: -1, plugin/k8s_external/msg_to_dns.go skips that service, plugin/k8s_external/transfer.go sends an empty []dns.RR batch, and plugin/transfer/transfer.go indexes records[0] without checking the batch is non-empty. This issue is fixed in version 1.14.5.","modified":"2026-08-30T05:26:50Z","published":"2026-07-16T20:16:47Z","upstream":["CVE-2026-62994"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62994"}],"affected":[{"package":{"name":"coredns","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/coredns"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.11.4-20"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92895.json"}}],"schema_version":"1.9.0"}