coredns v1.14.2 版本更新介绍
发布日期: 2026-03-06
版本号: v1.14.2
本次发布新增了proxyproto插件以支持代理协议,确保负载均衡器后的客户端IP得以保留。同时包含多项增强功能,如改进的DNS日志元数据、更强的环检测随机性(修复CVE-2026-26018),以及多个错误修复,涉及TLS+IPv6转发、CNAME处理与重写改进、允许禁用抖动、防止ACL绕过(修复CVE-2026-26017)和Kubernetes插件崩溃修复。此外,构建环境更新至Go 1.26.1,其中包含修复CVE-2026-27137、CVE-2026-27138、CVE-2026-27139、CVE-2026-25679和CVE-2026-27142等安全问题的更新。
更新内容 (中文)
此版本新增了proxyproto插件,用于支持代理协议并维护负载均衡器后的客户端IP。同时包含多项增强功能:改进的DNS日志元数据、更强的环路检测随机性(CVE-2026-26018),以及多项错误修复:包括TLS+IPv6转发、改进的CNAME处理与重写、允许禁用抖动、防止ACL绕过(CVE-2026-26017)和Kubernetes插件崩溃修复。此外,构建环境已升级至Go 1.26.1,该版本包含修复CVE-2026-27137、CVE-2026-27138、CVE-2026-27139、CVE-2026-25679及CVE-2026-27142的安全更新。
致谢贡献者
Adphi
Henrik Gerdes
hide
Kelly Kane
Shiv Tyagi
vflaux
Ville Vesilehto
yangsenzk
Yong Tang
YOUNEVSKY
重要变更
- 核心:调整重写规则在ACL之前执行以防止绕过 (https://github.com/coredns/coredns/pull/7882)
- file插件:当查询被CNAME指向原始域的记录时返回SOA和NS记录 (https://github.com/coredns/coredns/pull/7808)
- forward插件:修复处理TLS+IPv6地址时的解析错误 (https://github.com/coredns/coredns/pull/7848)
- log插件:为响应类型和类别添加元数据记录 (https://github.com/coredns/coredns/pull/7806)
- loop插件:使用crypto/rand生成查询名称以增强随机性 (https://github.com/coredns/coredns/pull/7881)
- kubernetes插件:修复ListenHosts为空时的panic崩溃 (https://github.com/coredns/coredns/pull/7857)
- proxyproto插件:新增代理协议支持 (https://github.com/coredns/coredns/pull/7738)
- reload插件:允许使用0s值禁用抖动 (https://github.com/coredns/coredns/pull/7896)
- rewrite插件:修复CNAME链中的目标重写问题 (https://github.com/coredns/coredns/pull/7853)
更新内容 (原始)
This release adds the new proxyproto plugin to support Proxy Protocol and preserve client IPs behind load balancers. It also includes enhancements such as improved DNS logging metadata and stronger randomness for loop detection (CVE-2026-26018), along with several bug fixes including TLS+IPv6 forwarding, improved CNAME handling and rewriting, allowing jitter disabling, prevention of an ACL bypass (CVE-2026-26017), and a Kubernetes plugin crash fix. In addition, the release updates the build to Go 1.26.1, which include security fixes addressing CVE-2026-27137, CVE-2026-27138, CVE-2026-27139, CVE-2026-25679, and CVE-2026-27142.
Brought to You By
Adphi Henrik Gerdes hide Kelly Kane Shiv Tyagi vflaux Ville Vesilehto yangsenzk Yong Tang YOUNEVSKY
Noteworthy Changes
- core: Reorder rewrite before acl to prevent bypass (https://github.com/coredns/coredns/pull/7882)
- plugin/file: Return SOA and NS records when queried for a record CNAMEd to origin (https://github.com/coredns/coredns/pull/7808)
- plugin/forward: Fix parsing error when handling TLS+IPv6 address (https://github.com/coredns/coredns/pull/7848)
- plugin/log: Add metadata for response Type and Class to Log (https://github.com/coredns/coredns/pull/7806)
- plugin/loop: Use crypto/rand for query name generation (https://github.com/coredns/coredns/pull/7881)
- plugin/kubernetes: Fix panic on empty ListenHosts (https://github.com/coredns/coredns/pull/7857)
- plugin/proxyproto: Add proxy protocol support (https://github.com/coredns/coredns/pull/7738)
- plugin/reload: Allow disabling jitter with 0s (https://github.com/coredns/coredns/pull/7896)
- plugin/rewrite: Fix cname target rewrite for CNAME chains (https://github.com/coredns/coredns/pull/7853)
下载链接
- coredns_1.14.2_darwin_amd64.tgz
- coredns_1.14.2_darwin_amd64.tgz.sha256
- coredns_1.14.2_darwin_arm64.tgz
- coredns_1.14.2_darwin_arm64.tgz.sha256
- coredns_1.14.2_linux_amd64.tgz
- coredns_1.14.2_linux_amd64.tgz.sha256
- coredns_1.14.2_linux_arm.tgz
- coredns_1.14.2_linux_arm.tgz.sha256
- coredns_1.14.2_linux_arm64.tgz
- coredns_1.14.2_linux_arm64.tgz.sha256
- coredns_1.14.2_linux_mips.tgz
- coredns_1.14.2_linux_mips.tgz.sha256
- coredns_1.14.2_linux_mips64le.tgz
- coredns_1.14.2_linux_mips64le.tgz.sha256
- coredns_1.14.2_linux_ppc64le.tgz
- coredns_1.14.2_linux_ppc64le.tgz.sha256
- coredns_1.14.2_linux_riscv64.tgz
- coredns_1.14.2_linux_riscv64.tgz.sha256
- coredns_1.14.2_linux_s390x.tgz
- coredns_1.14.2_linux_s390x.tgz.sha256
- coredns_1.14.2_windows_amd64.tgz
- coredns_1.14.2_windows_amd64.tgz.sha256