RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: CoreDNSClear ×
CoreDNSv1.14.7Kubernetes CoreAug 19, 2026

A maintenance release with a Go toolchain update that includes disclosed CVE fixes, an ACL-check bypass correction, and changes to operator-visible defaults. It also adds features and corrects defects across the DNS server.

Action needed (1)

Check if affected (3)

  • securityplugin/acl autopath ACL checks

    Applies if you use plugin/acl and autopath.

    The plugin/acl plugin fixes autopath bypassing ACL checks. This correction ships in the ACL plugin.

  • breakingplugin/forward default connection attempts

    Applies if you use plugin/forward.

    The plugin/forward plugin caps the default number of connection attempts. This default change ships in the forward plugin.

  • breakingplugin/hosts unsupported-type fallthrough

    Applies if you use plugin/hosts.

    The plugin/hosts plugin makes fallthrough for unsupported types opt-in. This default change ships in the hosts plugin.

Source
CoreDNSv1.14.3Kubernetes CoreApr 22, 2026

A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1.26.2, which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.

Action needed (1)

Check if affected (1)

  • breakingOversized DoH GET query parameter rejection

    Applies if you use DoH.

    CoreDNS rejects an oversized GET DNS query parameter in DoH.

Source
CoreDNSv1.14.2Kubernetes CoreMar 6, 2026

A maintenance release with proxy protocol support, operator-visible behavior changes, and several correctness fixes. It also updates the Go build dependency with cited security fixes and changes ACL-related and query-name handling.

Action needed (1)

Check if affected (2)

  • securityhighThe rewrite and acl ordering, CVE-2026-26017

    Applies if you use both rewrite and acl.

    Core reorders rewrite before acl to prevent an ACL bypass. This change addresses CVE-2026-26017.

  • securityhighplugin/loop query name generation, CVE-2026-26018

    Applies if plugin/loop runs.

    plugin/loop uses crypto/rand to generate query names. This change addresses CVE-2026-26018.

Source
CoreDNSv1.14.1Kubernetes CoreJan 16, 2026

A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.

Action needed (1)

  • securityhighCVE-2025-68119 fix

    The release also addresses CVE-2025-68119, which affects the stated Go versions.

Check if affected (1)

Source
Browse by month