{"id":"CVE-2019-19794","aliases":["GHSA-44r7-7p62-q3fr","GO-2020-0008"],"url":"https://o3.security/vulnerability/CVE-2019-19794","summary":"miekg/dns insecurely generates random numbers","details":"The miekg Go DNS package before 1.1.25, as used in CoreDNS before 1.6.6 and other products, improperly generates random numbers because math/rand is used. The TXID becomes predictable, leading to response forgeries.","published":"2019-12-13T22:15:11.357Z","modified":"2026-07-08T20:16:13.168729Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Go","name":"github.com/miekg/dns","fixedVersion":"1.1.25"}],"fix":{"url":"https://github.com/miekg/dns/pull/1044","label":"miekg/dns#1044"},"references":[{"type":"ADVISORY","url":"https://github.com/coredns/coredns/issues/3547"},{"type":"ADVISORY","url":"https://github.com/miekg/dns/compare/v1.1.24...v1.1.25"},{"type":"REPORT","url":"https://github.com/coredns/coredns/issues/3519"},{"type":"REPORT","url":"https://github.com/miekg/dns/issues/1043"},{"type":"FIX","url":"https://github.com/miekg/dns/pull/1044"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:16:13.168729Z"}}