NULL Pointer Dereference Affecting github.com/coredns/coredns/plugin/rewrite package, versions <1.14.5


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.54% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCOREDNSCOREDNSPLUGINREWRITE-18017742
  • published19 Jul 2026
  • disclosed16 Jul 2026
  • credit5ud0er

Introduced: 16 Jul 2026

CVE-2026-62299  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade github.com/coredns/coredns/plugin/rewrite to version 1.14.5 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference via the ResponseReverter. An attacker can cause the application to panic and degrade availability or crash the process by sending a specially crafted DNS query that triggers a nil pointer dereference when a downstream plugin returns a response with no OPT record.

Note: This is only exploitable if the debug directive disables recovery.

CVSS Base Scores

version 4.0
version 3.1