Resource exhaustion in AdGuard Home - #VU137481
Published: July 14, 2026
AdGuard Home
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the DNS-over-QUIC listener and request-processing budget handling when accepting idle QUIC connections or incomplete DoQ streams. A remote attacker can open idle QUIC connections or send partial DoQ streams to cause a denial of service.
Because the request-processing budget is shared across multiple DNS frontends, exhausting it through the DoQ listener can stall or block unrelated DNS traffic handled by the same server instance.