Buffer Overflow Vulnerability in CoreDNS from Cloudflare
CVE-2026-82399

7.5HIGH

Key Information:

Vendor

Coredns

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-82399?

A buffer overflow vulnerability in CoreDNS, a DNS server developed in Go, allows unauthenticated clients to manipulate DNS section counts, leading to potential memory exhaustion. This can occur in various request paths before validation occurs, enabling attackers to exploit DNS name compression alongside excessive section counts. As a result, memory allocation can be overwhelmed, potentially terminating the CoreDNS service. This vulnerability does not affect UDP and TCP listeners due to their header validation mechanism. The issue has been resolved in version 1.14.7.

Affected Version(s)

coredns < 1.14.7

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.