Buffer Overflow Vulnerability in CoreDNS from Cloudflare
CVE-2026-82399
7.5HIGH
What is CVE-2026-82399?
A buffer overflow vulnerability in CoreDNS, a DNS server developed in Go, allows unauthenticated clients to manipulate DNS section counts, leading to potential memory exhaustion. This can occur in various request paths before validation occurs, enabling attackers to exploit DNS name compression alongside excessive section counts. As a result, memory allocation can be overwhelmed, potentially terminating the CoreDNS service. This vulnerability does not affect UDP and TCP listeners due to their header validation mechanism. The issue has been resolved in version 1.14.7.
Affected Version(s)
coredns < 1.14.7
