PT-2026-37095 · Coredns · Coredns

Thesmartshadow

·

Published

2026-04-28

·

Updated

2026-05-06

·

CVE-2026-32936

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.3
Description CoreDNS is a DNS server that chains plugins. A denial-of-service issue exists in the DNS-over-HTTPS (DoH) GET path because it lacks early size validation for requests. A remote, unauthenticated attacker can send oversized requests to the '/dns-query' endpoint using the dns query parameter. The server performs expensive operations—including URL query parsing, base64 decoding via the base64ToMsg() function, and DNS message unpacking—before rejecting the request with a 400 Bad Request error.
This process forces high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, which can lead to degraded throughput and responsiveness or a complete denial of service, particularly on memory-constrained deployments.
Recommendations Update to version 1.14.3. As a temporary workaround, restrict access to the '/dns-query' endpoint or implement a web application firewall (WAF) to limit the size of GET request targets and the dns parameter.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-32936
GHSA-63CW-R7XF-JMWR

Affected Products

Coredns