PT-2026-93903 · Coredns · Coredns
CVE-2026-82399
·
Published
2026-07-16
·
Updated
2026-09-28
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
CoreDNS versions prior to 1.14.7
Description
CoreDNS contains an unauthenticated denial-of-service issue where the server parses attacker-controlled DNS section counts before validating the fixed header. This occurs within the DNS-over-HTTPS (DoH and DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC request paths located in
plugin/pkg/doh/doh.go, core/dnsserver/server quic.go, and core/dnsserver/server grpc.go.An attacker can use DNS name compression and excessive section counts to trigger amplified memory allocation during the execution of the
dns.Msg.Unpack() function. For example, a single 65,533-byte request can allocate more than 10 MiB of memory. Because this parsing happens before the plugin chain, plugin-level rate limiting cannot prevent concurrent requests from exhausting system memory and causing the server to be terminated by the operating system (OOMKilled). Ordinary UDP and TCP listeners are not affected as they validate the header before unpacking.Recommendations
Update CoreDNS to version 1.14.7.
As a temporary mitigation, restrict access to the DNS-over-HTTPS, DNS-over-QUIC, and DNS-over-gRPC transports to trusted clients only.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coredns