{"schema_version":"1.7.5","id":"openSUSE-SU-2026:20703-1","published":"2026-05-06T17:18:02Z","modified":"2026-05-09T18:25:09.721860Z","related":["CVE-2026-27140","CVE-2026-27143","CVE-2026-27144","CVE-2026-32282","CVE-2026-32283","CVE-2026-32288","CVE-2026-32289","CVE-2026-32934","CVE-2026-32936","CVE-2026-33190","CVE-2026-33489","CVE-2026-33810","CVE-2026-35579"],"upstream":["CVE-2026-27140","CVE-2026-27143","CVE-2026-27144","CVE-2026-32282","CVE-2026-32283","CVE-2026-32288","CVE-2026-32289","CVE-2026-32934","CVE-2026-32936","CVE-2026-33190","CVE-2026-33489","CVE-2026-33810","CVE-2026-35579"],"summary":"Security update for coredns","details":"This update for coredns fixes the following issues:\n\nChanges in coredns:\n\n- Update to version 1.14.3:\n  * This release introduces Windows service support, along with full TSIG\n    verification across DoH, DoH3, QUIC, and gRPC transports, and improved\n    TSIG propagation and DoH request validation.\n  * It also adds optional TLS for the metrics endpoint.\n  * Performance and stability are improved through cache prefetching, QUIC\n    optimizations, and a new max_age option in the forward plugin.\n  * Additional updates include enhanced SVCB/HTTPS support, improved zone\n    transfer behavior, and various DNSSEC, PROXY protocol, and concurrency\n    fixes.\n  * The release is built with Go 1.26.2, which includes security\n    fixes addressing CVE-2026-32282, CVE-2026-32289, CVE-2026-33810,\n    CVE-2026-27144, CVE-2026-27143, CVE-2026-32288, CVE-2026-32283,\n    and CVE-2026-27140, and also includes fixes for CVE-2026-32936,\n    CVE-2026-33190, CVE-2026-33489, CVE-2026-32934, and CVE-2026-35579.\n","references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27140"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32282"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32283"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32288"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32289"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-32936"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33190"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33489"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-35579"}]}