SB2026071461 - Resource exhaustion in AdGuard Home



SB2026071461 - Resource exhaustion in AdGuard Home

Published: July 14, 2026

Security Bulletin ID SB2026071461
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Resource exhaustion (CVE-ID: N/A)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource management in the DNS-over-QUIC listener and request-processing budget handling when accepting idle QUIC connections or incomplete DoQ streams. A remote attacker can open idle QUIC connections or send partial DoQ streams to cause a denial of service.

Because the request-processing budget is shared across multiple DNS frontends, exhausting it through the DoQ listener can stall or block unrelated DNS traffic handled by the same server instance.


Remediation

Install update from vendor's website.