PT-2026-37095 · Coredns · Coredns

·

CVE-2026-32936

·

Published

2026-04-28

·

Updated

2026-06-25

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.3
Description CoreDNS is a DNS server that chains plugins. A denial-of-service issue exists in the DNS-over-HTTPS (DoH) GET path because it lacks early size validation for requests. A remote, unauthenticated attacker can send oversized requests to the '/dns-query' endpoint using the dns query parameter. The server performs expensive operations—including URL query parsing, base64 decoding via the base64ToMsg() function, and DNS message unpacking—before rejecting the request with a 400 Bad Request error.
This process forces high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, which can lead to degraded throughput and responsiveness or a complete denial of service, particularly on memory-constrained deployments.
Recommendations Update to version 1.14.3. As a temporary workaround, restrict access to the '/dns-query' endpoint or implement a web application firewall (WAF) to limit the size of GET request targets and the dns parameter.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CLEANSTART-2026-SL86558
CLEANSTART-2026-VJ54611
CVE-2026-32936
GHSA-63CW-R7XF-JMWR
GO-2026-5164
OPENSUSE-SU-2026:20703-1

Affected Products

Coredns