Threat Advisory

CoreDNS Flaw Causes Unauthenticated Memory Exhaustion

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version 1.14.7 and earlier. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to memory exhaustion or bypassing of security features.

CVE-2026-82399 (CVSS 5.3 — Medium): An unauthenticated attacker can cause memory exhaustion in custom transports of CoreDNS, leading to denial-of-service conditions.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in github., affecting version 1.14.7 and earlier. These vulnerabilities pose a moderate to high risk of exploitation, potentially leading to memory exhaustion or bypassing of security features.

CVE-2026-82399 (CVSS 5.3 — Medium): An unauthenticated attacker can cause memory exhaustion in custom transports of CoreDNS, leading to denial-of-service conditions.[emaillocker id="1283"]

CVE-2026-86003: An attacker can bypass security features by exploiting a bypass UPDATE rejection enforced on UDP/TCP in CoreDNS.

These vulnerabilities collectively present a moderate risk to administrators who have not applied the latest updates.

RECOMMENDATION:

We recommend you to update coredns to version 1.14.7

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu