Executive brief
Technitium DNS Server is an open-source tool used for self-hosting DNS services to improve privacy and security. A vulnerability in versions 14.3 and earlier allows a remote attacker to crash the server or make it unresponsive. This could lead to a total loss of DNS services for the network, preventing users from accessing websites or internal resources.
Technical details
A denial of service (DoS) vulnerability exists in Technitium DNS Server versions 14.3 and prior. The flaw is located within the DnsServerApp.exe, DnsServerApp.dll, and the TechnitiumLibrary.Net/Dns/DnsClient.cs components. A remote, unauthenticated attacker can exploit this issue via the network to cause the DNS service to become unavailable. While specific exploitation details are not provided in the advisory, the affected components suggest the issue may be triggered during the processing of DNS queries or client requests. Users should upgrade to a newer version (such as v15.x) to mitigate this risk.
Affected products
- Technitium DNS Server v14.3 and earlier
Timeline
- 2026-06-26: disclosed: CVE-2026-36478 published