Back to VulnFeed / CVE-2026-32934
root@hackertop:~/vulnfeed/CVE-2026-32934#
CVE-2026-32934 MEDIUM RCE ⚠ Unpatched · Zero-day◉ PoC 公开 Lifecycle 4/7

CoreDNS 1.12.2/1.12.4/1.14.0/1.14.2 DoQ Worker Pool allocation of resources

CoreDNS 21d ago Impact pending confirmation
LIFECYCLE
5.1 CVSS
Vulnerability Detail Mitigation Lifecycle CVSS Assessment
Vulnerability Description
A vulnerability, which was classified as problematic, was found in CoreDNS 1.12.2/1.12.4/1.14.0/1.14.2. This affects an unknown code block of the component DoQ Worker Pool. Upgrading to version 1.14.3 eliminates this vulnerability.
Root Cause Analysis
CWE is classifying the issue as CWE-770. The product allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.

Impact: This is going to have an impact on availability.

Countermeasure: Upgrading to version 1.14.3 eliminates this vulnerability.
Validation (PoC/EXP) - Looking for Contributors
No public PoC yet

Public validation traces already exist. Community contributors can extend them with richer reproduction content.

Contribute Your PoC/EXP
Log in to contribute PoC/EXP content. Log in
Back to VulnFeed
CVE-2026-32934 · CVSS 5.1 · Active Threat