Impact
CoreDNS can be forced to allocate excessive memory when processing DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC packets that contain attacker-crafted name compression and an inflated number of DNS sections. The allocation happens before the standard header checks, so a client that does not need to be authenticated can send a single request that causes the server to consume more memory than intended, eventually leading to a crash. The weakness is a reuse of DNS messages that bypasses normal validation and results in resource exhaustion. This makes the affected CoreDNS instances vulnerable to denial-of-service attacks but does not provide a path to execute code or bypass authentication.
Affected Systems
All CoreDNS installations running a version earlier than 1.14.7 are affected. The issue occurs in the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths within the core/dnsserver and plugin/pkg/doh components. Affected vendors are coredns:coredns. Versions 1.14.7 and newer incorporate the fix, so any release equal to or newer than 1.14.7 is considered safe.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating a high‑severity denial‑of‑service risk. The EPSS score is below 1%, showing that widespread exploitation is unlikely at present. CoreDNS is not listed in the CISA KEV catalog. An attacker only needs to be able to send packets over the four mentioned transports, without authentication, and can amplify the memory allocation by using name compression and excessive section counts. Because plugin‑level rate limiting cannot stop the attack, an unauthenticated client can generate many concurrent requests, causing the server to exhaust memory and terminate.
OpenCVE Enrichment
Github GHSA