PT-2026-37094 · Coredns+1 · Coredns+1

·

CVE-2026-32934

·

Published

2026-04-28

·

Updated

2026-07-30

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.3
Description The DNS-over-QUIC (DoQ) server can be forced into unbounded goroutine and memory growth by a remote unauthenticated client. This occurs when a client opens numerous QUIC streams and sends only one byte per stream. Even when the worker pool is full, the system continues to spawn a goroutine for every accepted stream to wait for a worker token. Furthermore, active workers can block indefinitely in the io.ReadFull() function because there is no per-stream read deadline, allowing an attacker to pin all workers by sending a single byte while the system waits for the second byte of the DoQ length prefix. This leads to memory exhaustion and an OOM-kill (Out-of-Memory kill), resulting in a denial of service.
Recommendations Update to version 1.14.3.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SL86558
CLEANSTART-2026-VJ54611
CVE-2026-32934
GHSA-2WPX-QPW2-G5H5
GO-2026-4969
OPENSUSE-SU-2026:20703-1
OPENSUSE-SU-2026:21483-1

Affected Products

Coredns
Red Os