THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mrg3-qvqr-jw29 (high) — CoreDNS: Unauthenticated memory exhaustion in custom transports

[GHSA] GHSA-mrg3-qvqr-jw29 (high) — CoreDNS: Unauthenticated memory exhaustion in custom transports

highgithub_advisoriesPublished 2026-09-17

GHSA-mrg3-qvqr-jw29 Severity: high CVE: CVE-2026-82399

CoreDNS: Unauthenticated memory exhaustion in custom transports

### Summary

CoreDNS parses attacker-controlled DNS section counts before validating them on DNS-over-HTTPS (DoH and DoH3), DNS-over-QUIC (DoQ), and DNS-over-gRPC listeners. An unauthenticated client can use DNS name compression to make one 65,533-byte request allocate more than

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mrg3-qvqr-jw29