CVE-2019-19794: Miekg-DNS Project Miekg-DNS
Medium severity, CVSS 5.9. EPSS: 2.1% chance of exploitation in the next 30 days.
The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.
Affected products
- Miekg-DNS Project Miekg-DNS: before 1.1.25 (fixed in 1.1.25)
Published 2019-12-13. Last modified 2026-06-17.