CVE-2025-68151

Name
CVE-2025-68151
Description
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An unauthenticated remote attacker can exhaust memory and degrade or crash the server by opening many concurrent connections, streams, or sending oversized request bodies. The issue is similar in nature to CVE-2025-47950 (QUIC DoS) but affects additional server types that do not enforce connection limits, stream limits, or message size constraints. Version 1.14.0 contains a patch.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/coredns/coredns/commit/0d8cbb1a6bcb6bc9c1a489865278b8725fa20812
MISC https://github.com/coredns/coredns/pull/7490
CONFIRM https://github.com/coredns/coredns/security/advisories/GHSA-527x-5wrf-22m2

Match rules

CPE URI Source package Min version Max version
coredns >= 0 < 1.14.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
coredns edge-community 1.13.2-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns edge-community 1.13.2-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns edge-community 1.12.3-r5 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns edge-community 1.12.3-r4 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns edge-community 1.12.3-r3 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns edge-community 1.12.3-r2 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns edge-community 1.12.3-r1 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.3-r0 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.2-r1 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.2-r0 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.1-r2 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.1-r1 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.1-r0 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.0-r5 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.0-r4 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.0-r3 fossdd <fossdd@pwned.life> possibly vulnerable
coredns edge-community 1.12.0-r1 Mark Pashmfouroush <mark@markpash.me> possibly vulnerable
coredns edge-community 1.12.0-r0 Mark Pashmfouroush <mark@markpash.me> possibly vulnerable
coredns edge-community 1.11.3-r0 Mark Pashmfouroush <mark@markpash.me> possibly vulnerable
coredns edge-community 1.9.3-r0 Mark Pashmfouroush <mark@markpash.me> possibly vulnerable
coredns 3.23-community 1.12.3-r6 Achill Gilgenast <achill@achill.org> possibly vulnerable
coredns 3.23-community 1.12.3-r5 Achill Gilgenast <achill@achill.org> possibly vulnerable