CVE-2026-33190Disclosure(coredns.io / coredns)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch coredns.io coredns systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it trusts the transport writer's TsigStatus() instead of performing verification itself. The DoH and DoH3 writer's TsigStatus() always returns nil, the DoT server does not set TsigSecret on the dns.Server, and the DoQ and gRPC writers also unconditionally return nil. This allows an unauthenticated remote client to bypass TSIG-based authentication and access resources intended to be restricted behind a tsig require all policy. Plain DNS over TCP and UDP are not affected. This issue has been fixed in version 1.14.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-303

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • coredns

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-05-05); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
coredns

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-04-29: 1Mentions · 2026-04-30: 1Mentions · 2026-05-05: 2Mentions · 2026-05-06: 1Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-04-29: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-06: 1Technical Details · 2026-05-13: 104-2904-3005-0505-0605-13
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-291
Disclosure1
2026-04-301
Disclosure1
2026-05-052
Disclosure2
2026-05-061
General1
2026-05-131
Patch1
Full discourse6 posts
  • 𝔸𝕟𝕠𝕟𝕪𝕞𝕠𝕦𝕤 ℍ𝕒𝕔𝕜𝕥𝕚𝕧𝕚𝕤𝕥☭⃠🅇@YourAnon_irc
    Patch

    Critical DNS flaws: Windows DNS Client RCE (CVE-2026-41096), dnsmasq bugs, & CoreDNS TSIG bypass (CVE-2026-33190) expose data privacy & integrity in transit. Patch ASAP! #Cybersecurity #NetworkSecurity #DNS

    Post summary

    The tweet alerts to newly disclosed DNS vulnerabilities affecting Windows DNS Client and CoreDNS, stressing the need for urgent patching.

    01052496
    15 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33190 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) … https://www.cve.org/CVERecord?id=CVE-2026-33190

    Post summary

    The post announces CVE-2026-33190, detailing that CoreDNS versions before 1.14.3 allow attackers to bypass the tsig plugin on secure DNS transports, but it does not mention PoC, exploitation tools, patches, or false positives.

    00010396
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Unpopular opinion: The cybersecurity industry is selling you dashboards. The DNS Foundation Cracks: CoreDNS CVE-2026-33190 Exposes TSIG Auth Bypass on Modern Transports

    Post summary

    The post references CoreDNS CVE‑2026‑33190 as a TSIG authentication bypass in modern transports, but provides no PoC, exploit tool, active usage, or patch information.

    1000024
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33190 TSIG Authentication Bypass in CoreDNS Versions Prior to 1.14.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33190

    Post summary

    The post briefly references CVE-2026-33190, noting a TSIG authentication bypass in CoreDNS before v1.14.3, and links to a external vulnerability details page.

    0000030
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-33190 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) … https://www.cve.org/CVERecord?id=CVE-2026-33190 ----- Traducción: CVE-2026-33190 Cor… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑33190, describing a tsig plugin bypass on various secure DNS transports, without mentioning PoC, exploit code, patches, or active exploitation.

    00000141
    75 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 CoreDNS, TSIG Authentication Bypass, #CVE-2026-33190 (High) https://dailycve.com/coredns-tsig-authentication-bypass-cve-2026-33190-high/

    Post summary

    A newly disclosed CoreDNS TSIG authentication bypass (CVE‑2026‑33190) is announced with high severity, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000050
    187 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcoredns.iocoredns---

Explore more