CVE-2019-19794: Miekg-DNS Project Miekg-DNS

Medium severity, CVSS 5.9. EPSS: 2.1% chance of exploitation in the next 30 days.

The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.

Affected products

Published 2019-12-13. Last modified 2026-06-17.