RATATOSKRATATOSK
Sign in

Releases

AI-analyzed release notes for CNCF graduated and incubating projects.

Project: CoreDNSClear ×
CoreDNSv1.14.7Kubernetes CoreAug 19, 2026

A maintenance release with a Go toolchain update that includes disclosed CVE fixes, an ACL-check bypass correction, and changes to operator-visible defaults. It also adds features and corrects defects across the DNS server.

Action needed (1)

Check if affected (3)

  • securityplugin/acl autopath ACL checks

    Applies if you use plugin/acl and autopath.

    The plugin/acl plugin fixes autopath bypassing ACL checks. This correction ships in the ACL plugin.

  • breakingplugin/forward default connection attempts

    Applies if you use plugin/forward.

    The plugin/forward plugin caps the default number of connection attempts. This default change ships in the forward plugin.

  • breakingplugin/hosts unsupported-type fallthrough

    Applies if you use plugin/hosts.

    The plugin/hosts plugin makes fallthrough for unsupported types opt-in. This default change ships in the hosts plugin.

Source
CoreDNSv1.14.6Kubernetes CoreJul 10, 2026

This release changes dependency composition and CoreDNS behavior. It adds a forward plugin directive and expands secondary-plugin zone support, while also addressing a non-64-bit build defect through a dependency adjustment.

Source
CoreDNSv1.14.5Kubernetes CoreJul 10, 2026

A release with operator-visible behavior corrections, new capabilities, configuration changes, and updated defaults. The changes span CoreDNS core behavior and multiple plugins, with no security advisories or explicitly described vulnerabilities.

Action needed (1)

  • breakingGo TLS defaults in core

    The core component uses Go TLS defaults in this release.

Check if affected (1)

  • breakingDefault truncate amount for bare truncate

    Applies if you configure truncate.

    The plugin/erratic plugin applies a default truncate amount of 2 when the bare truncate configuration is used.

Source
CoreDNSv1.14.4Kubernetes CoreJun 9, 2026

A release with new plugin capabilities, stricter validation, DNS and cache behavior changes, expanded platform support, and malformed-input handling fixes. The HTTP/3 request header limit is narrowed for DoH3.

Check if affected (1)

  • breakingBound DoH3 HTTP/3 request header size

    Applies if you use DoH3.

    Core now bounds the HTTP/3 request header size for DoH3.

Source
CoreDNSv1.14.3Kubernetes CoreApr 22, 2026

A maintenance release that adds operator-facing options and transport, plugin, and protocol support while correcting defects. It is built with Go 1.26.2, which contains fixes for disclosed CVEs; other changes concern operators using the affected features or behaviors.

Action needed (1)

Check if affected (1)

  • breakingOversized DoH GET query parameter rejection

    Applies if you use DoH.

    CoreDNS rejects an oversized GET DNS query parameter in DoH.

Source
CoreDNSv1.14.2Kubernetes CoreMar 6, 2026

A maintenance release with proxy protocol support, operator-visible behavior changes, and several correctness fixes. It also updates the Go build dependency with cited security fixes and changes ACL-related and query-name handling.

Action needed (1)

Check if affected (2)

  • securityhighThe rewrite and acl ordering, CVE-2026-26017

    Applies if you use both rewrite and acl.

    Core reorders rewrite before acl to prevent an ACL bypass. This change addresses CVE-2026-26017.

  • securityhighplugin/loop query name generation, CVE-2026-26018

    Applies if plugin/loop runs.

    plugin/loop uses crypto/rand to generate query names. This change addresses CVE-2026-26018.

Source
CoreDNSv1.14.1Kubernetes CoreJan 16, 2026

A security-focused maintenance release addresses disclosed Go vulnerabilities and improves proxy connection-pool performance. It also adds the forward plugin's max_idle_conns parameter, which defaults to 0 for an unbounded pool.

Action needed (1)

  • securityhighCVE-2025-68119 fix

    The release also addresses CVE-2025-68119, which affects the stated Go versions.

Check if affected (1)

Source
CoreDNSv1.14.0Kubernetes CoreJan 8, 2026

A maintenance release with a new regex length constraint, correctness fixes, and plugin capability and behavior changes. It does not disclose a security advisory or explicitly exploitable vulnerability.

Action needed (1)

  • breakingThe core regex length limit

    core adds a length limit for regular expressions.

Source
Browse by month