CVE-2026-32936
CoreDNS DoH GET path missing size validation causes CPU and memory amplification
Description
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3.
INFO
Published Date :
May 5, 2026, 8:16 p.m.
Last Modified :
July 25, 2026, 11:10 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | [email protected] | ||||
| CVSS 4.0 | HIGH | [email protected] |
Solution
- Update CoreDNS to version 1.14.3.
- Ensure DoH GET requests have size validation.
- Monitor CPU and memory usage.
Public PoC/Exploit Available at Github
CVE-2026-32936 has a 1 public
PoC/Exploit available at Github.
Go to the Public Exploits tab to see the list.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-32936.
| URL | Resource |
|---|---|
| https://github.com/coredns/coredns/releases/tag/v1.14.3 | Release Notes |
| https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr | Exploit Mitigation Vendor Advisory |
| https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr | Exploit Mitigation Vendor Advisory |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-32936 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-32936
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
None
Python
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-32936 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-32936 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 25, 2026
Action Type Old Value New Value Added Translation Title: CoreDNS, Description: CoreDNS es un servidor DNS que encadena complementos. En versiones anteriores a la 1.14.3, la ruta GET de DNS-over-HTTPS (DoH) acepta valores de parámetros de consulta 'dns=' sobredimensionados y realiza el análisis de la consulta URL, la decodificación base64 y el desempaquetado del mensaje DNS antes de rechazar la solicitud. A diferencia de la ruta POST, que aplica una lectura acotada a través de http.MaxBytesReader limitada a 65536 bytes, la ruta GET no tiene una validación de tamaño equivalente antes de un procesamiento costoso. Un atacante remoto no autenticado puede enviar repetidamente solicitudes GET de DoH sobredimensionadas para forzar un alto uso de CPU, grandes asignaciones de memoria transitoria y una presión elevada de recolección de basura, lo que lleva a una denegación de servicio. Este problema ha sido solucionado en la versión 1.14.3. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'coredns', 'product': 'coredns', 'versions': [{'status': 'affected', 'version': '< 1.14.3'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-32936', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'poc'}, {'automatable': 'yes'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-05-05T19:32:21.653054Z'} -
Initial Analysis by [email protected]
May. 08, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Added CPE Configuration OR *cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:* versions up to (excluding) 1.14.3 Added Reference Type GitHub, Inc.: https://github.com/coredns/coredns/releases/tag/v1.14.3 Types: Release Notes Added Reference Type CISA-ADP: https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr Types: Exploit, Mitigation, Vendor Advisory Added Reference Type GitHub, Inc.: https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr Types: Exploit, Mitigation, Vendor Advisory -
New CVE Received by [email protected]
May. 05, 2026
Action Type Old Value New Value Added Description CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decoding, and DNS message unpacking before rejecting the request. Unlike the POST path, which applies a bounded read via http.MaxBytesReader limited to 65536 bytes, the GET path has no equivalent size validation before expensive processing. A remote, unauthenticated attacker can repeatedly send oversized DoH GET requests to force high CPU usage, large transient memory allocations, and elevated garbage-collection pressure, leading to denial of service. This issue has been fixed in version 1.14.3. Added CVSS V4.0 AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Added CWE CWE-400 Added Reference https://github.com/coredns/coredns/releases/tag/v1.14.3 Added Reference https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
May. 05, 2026
Action Type Old Value New Value Added Reference https://github.com/coredns/coredns/security/advisories/GHSA-63cw-r7xf-jmwr