Trail of Bits (https://trailofbits.com) conducted a security review and threat model of CoreDNS. Quoting from the security review summary: “The audit uncovered one high-severity issue (TOB-CDNS-8) concerning a bug that could lead to cache poisoning attacks. The majority of the other issues are of informational or low severity; these include several resulting from insufficient data validation, specifically from assumptions about the data processed by various functions, which we discovered by running fuzzing harnesses.