Junglewise Threat Intelligence
CVE-2025-47950: GO-2025-3743 - CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification in github.com/coredns/coredns
CVE-2025-47950 · Severity: low · CVSS 3.1 · Published 2025-06-10
Technologies: github.com/coredns/coredns (Go). Vendors: Go.
Executive brief
CoreDNS Vulnerable to DoQ Memory Exhaustion via Stream Amplification in github.com/coredns/coredns
Affected products
- Go github.com/coredns/coredns
Related threats
- CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC listeners in p
- CoreDNS is a DNS server written in Go. Prior to 1.14.7, the DNS-over-HTTPS, DNS-over-HTTP/3, DNS-over-QUIC, and DNS-over-gRPC request paths
- CoreDNS TSIG authentication bypass in gRPC, QUIC, and DoH transports
- CoreDNS incorrect authorization in transfer plugin ACL selection
- CoreDNS tsig authentication bypass in encrypted transports