CVE-2025-47950 is a Denial of Service (DoS) vulnerability affecting CoreDNS versions prior to 1.12.2, specifically within its DNS-over-QUIC (DoQ) server implementation. An unauthenticated remote attacker can exploit this by opening an excessive number of QUIC streams, leading to uncontrolled memory consumption and an Out Of Memory (OOM) crash, particularly in resource-constrained environments. The vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.12.2CPE matchmatch criteria | cpe:2.3:a:coredns.io:coredns:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
Jun 10, 2025CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
Jun 6, 2025coredns: CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification
Jun 6, 2025