Количество 7
Количество 7
GHSA-63cw-r7xf-jmwr
CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification
CVE-2026-32936
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.
CVE-2026-32936
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.
CVE-2026-32936
CoreDNS DoH GET path missing size validation causes CPU and memory amplification
CVE-2026-32936
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14 ...
ROS-20260729-73-0027
Уязвимость coredns
openSUSE-SU-2026:20703-1
Security update for coredns
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-63cw-r7xf-jmwr CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-32936 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-32936 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3. | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-32936 CoreDNS DoH GET path missing size validation causes CPU and memory amplification | 1% Низкий | 3 месяца назад | ||
CVE-2026-32936 CoreDNS is a DNS server that chains plugins. In versions prior to 1.14 ... | CVSS3: 7.5 | 1% Низкий | 3 месяца назад | |
ROS-20260729-73-0027 Уязвимость coredns | CVSS3: 7.5 | 1% Низкий | 10 дней назад | |
openSUSE-SU-2026:20703-1 Security update for coredns | 3 месяца назад |
Уязвимостей на страницу