Allocation of Resources Without Limits or Throttling in CoreDNS - CVE-2026-82399
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in custom DNS request transport handlers when parsing crafted DNS messages on DNS-over-HTTPS, DNS-over-QUIC, or DNS-over-gRPC listeners. A remote attacker can send a specially crafted request to cause a denial of service.
Only deployments exposing DoH, DoH3, DoQ, or DNS-over-gRPC to an attacker are vulnerable, while ordinary UDP and TCP listeners are not affected.