{"id":"GO-2024-3134","summary":"CoreDNS Cache Poisoning via a birthday attack in github.com/coredns/coredns","details":"CoreDNS enables attackers to achieve DNS cache poisoning and inject fake responses via a birthday attack.","aliases":["CVE-2023-30464","GHSA-h92q-fgpp-qhrq"],"modified":"2026-02-04T04:26:57.501234Z","published":"2024-09-25T17:43:58Z","related":["CGA-2m4x-9m4p-3gh7"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-3134"},"references":[{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h92q-fgpp-qhrq"},{"type":"FIX","url":"https://github.com/coredns/coredns/commit/604a902e2c7e0317aecaa3666124079c75a31573"},{"type":"WEB","url":"https://gist.github.com/idealeer/e41c7fb3b661d4262d0b6f21e12168ba"}],"affected":[{"package":{"name":"github.com/coredns/coredns","ecosystem":"Go","purl":"pkg:golang/github.com/coredns/coredns"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.11.0"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/coredns/coredns/plugin/pkg/proxy","symbols":["Proxy.Connect"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-3134.json"}}],"schema_version":"1.7.3"}