Executive brief
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages in github.com/coredns/coredns
Affected products
- Go github.com/coredns/coredns
Junglewise Threat Intelligence
CVE-2025-68151 · Severity: medium · CVSS 4 · Published 2026-01-12
Technologies: github.com/coredns/coredns (Go). Vendors: Go.
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages in github.com/coredns/coredns