Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 7

Количество 7

redhat логотип

CVE-2026-32936

3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-32936

3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-32936

3 месяца назад

CoreDNS DoH GET path missing size validation causes CPU and memory amplification

EPSS: Низкий
debian логотип

CVE-2026-32936

3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14 ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260729-73-0027

10 дней назад

Уязвимость coredns

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-63cw-r7xf-jmwr

3 месяца назад

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20703-1

3 месяца назад

Security update for coredns

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-32936

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.

CVSS3: 7.5
1%
Низкий
3 месяца назад
nvd логотип
CVE-2026-32936

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.

CVSS3: 7.5
1%
Низкий
3 месяца назад
msrc логотип
CVE-2026-32936

CoreDNS DoH GET path missing size validation causes CPU and memory amplification

1%
Низкий
3 месяца назад
debian логотип
CVE-2026-32936

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14 ...

CVSS3: 7.5
1%
Низкий
3 месяца назад
redos логотип
ROS-20260729-73-0027

Уязвимость coredns

CVSS3: 7.5
1%
Низкий
10 дней назад
github логотип
GHSA-63cw-r7xf-jmwr

CoreDNS DoH GET oversized dns= query parameter causes pre-validation CPU and memory amplification

CVSS3: 7.5
1%
Низкий
3 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20703-1

Security update for coredns

3 месяца назад

Уязвимостей на страницу