Skip to content
archivevulnerability · 17 Sep 2026 · 20:32 UTC

GHSA-mrg3-qvqr-jw29: CoreDNS: Unauthenticated memory exhaustion in custom transports

VULNCVE-2026-82399source · GTH
HIGHHigh-risk vulnerability — CVSS 7.5

last 60 dispatches · spectrum

### Summary CoreDNS parses attacker-controlled DNS section counts before validating them on DNS-over-HTTPS (DoH and DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC listeners. An unauthenticated client can use DNS name compression to make one 65,533-byte request allocate more than 10 MiB while it is unpacked. Concurrent requests can exhaust memory and terminate CoreDNS. ### Details The affected request paths call `dns.Msg.Unpack` directly: - [DoH POST and GET decoding](https://github.com/coredns/coredns/blob/18a58b9e898ccd95c3f8ee72a37b95b3d1e3e928/plugin/pkg/doh/doh.go#L134-L155). …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected