PT-2026-93903 · Coredns · Coredns

CVE-2026-82399

·

Published

2026-07-16

·

Updated

2026-09-28

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.7
Description CoreDNS contains an unauthenticated denial-of-service issue where the server parses attacker-controlled DNS section counts before validating the fixed header. This occurs within the DNS-over-HTTPS (DoH and DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC request paths located in plugin/pkg/doh/doh.go, core/dnsserver/server quic.go, and core/dnsserver/server grpc.go.
An attacker can use DNS name compression and excessive section counts to trigger amplified memory allocation during the execution of the dns.Msg.Unpack() function. For example, a single 65,533-byte request can allocate more than 10 MiB of memory. Because this parsing happens before the plugin chain, plugin-level rate limiting cannot prevent concurrent requests from exhausting system memory and causing the server to be terminated by the operating system (OOMKilled). Ordinary UDP and TCP listeners are not affected as they validate the header before unpacking.
Recommendations Update CoreDNS to version 1.14.7. As a temporary mitigation, restrict access to the DNS-over-HTTPS, DNS-over-QUIC, and DNS-over-gRPC transports to trusted clients only.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-101838
BDU:2026-14834
CVE-2026-82399
ECHO-45C5-EAFD-F64C
GHSA-MRG3-QVQR-JW29
GO-2026-6507

Affected Products

Coredns