The SentinelOne Annual Threat Report - A Defenders Guide from the FrontlinesThe SentinelOne Annual Threat ReportGet the Report
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-32936

CVE-2026-32936: CoreDNS DNS-over-HTTPS DoS Vulnerability

CVE-2026-32936 is a denial of service flaw in CoreDNS DNS-over-HTTPS that allows attackers to exhaust CPU and memory resources via oversized GET requests. This article covers technical details, affected versions, and mitigations.

Published: May 7, 2026

CVE-2026-32936 Overview

CVE-2026-32936 is a denial-of-service vulnerability in CoreDNS, the plugin-based DNS server widely deployed in Kubernetes clusters and cloud-native environments. The flaw exists in the DNS-over-HTTPS (DoH) GET request handler in versions prior to 1.14.3. The GET path accepts oversized dns= query parameter values and performs URL parsing, base64 decoding, and DNS message unpacking before any size validation occurs. Unlike the POST path, which enforces a 65536-byte limit through http.MaxBytesReader, the GET path lacks an equivalent bound. A remote, unauthenticated attacker can abuse this asymmetry to exhaust CPU, memory, and garbage-collector resources on the server.

Critical Impact

Unauthenticated remote attackers can degrade or disable CoreDNS resolvers by sending oversized DoH GET requests, disrupting DNS resolution for every dependent workload.

Affected Products

  • CoreDNS versions prior to 1.14.3
  • Deployments exposing the DNS-over-HTTPS (DoH) GET endpoint
  • Kubernetes clusters and cloud-native environments running affected CoreDNS builds

Discovery Timeline

  • 2026-05-05 - CVE CVE-2026-32936 published to NVD
  • 2026-05-07 - Last updated in NVD database

Technical Details for CVE-2026-32936

Vulnerability Analysis

The vulnerability is a resource exhaustion issue classified under [CWE-400]. CoreDNS implements DoH per RFC 8484, which permits queries via either HTTP POST or HTTP GET. For POST requests, the server wraps the request body in http.MaxBytesReader with a 65536-byte cap, terminating reads that exceed the bound. For GET requests, the encoded DNS message arrives in the dns= URL query parameter, and CoreDNS processes it without first validating the parameter length.

The handler performs URL query parsing, then base64 decoding of the dns= value, then DNS message unpacking. Each stage allocates buffers proportional to the attacker-controlled input. By repeatedly issuing oversized GET requests, an attacker forces sustained CPU consumption, large transient heap allocations, and aggressive Go garbage-collection cycles. The cumulative effect degrades query latency and can render the resolver unresponsive.

Root Cause

The root cause is inconsistent input validation between the DoH POST and GET code paths. The POST path enforces a bounded read before decoding, while the GET path defers all size checks until after expensive parsing operations have already executed. This asymmetry allows attacker-controlled data to drive resource-intensive work prior to rejection.

Attack Vector

Exploitation requires only network access to the DoH endpoint and no authentication or user interaction. An attacker constructs HTTP GET requests with an oversized dns= query parameter value and sends them in volume. Because CoreDNS frequently sits at the core of Kubernetes service discovery, a successful attack disrupts intra-cluster name resolution and any downstream service relying on it. See the GitHub Security Advisory GHSA-63cw-r7xf-jmwr for additional technical context.

Detection Methods for CVE-2026-32936

Indicators of Compromise

  • Spikes in CoreDNS process CPU utilization and resident memory not correlated with legitimate query volume.
  • HTTP access logs showing a high rate of DoH GET requests with abnormally long dns= query parameter values.
  • Increased Go runtime garbage-collection metrics (go_gc_duration_seconds, heap allocations) reported by CoreDNS Prometheus exporters.
  • Elevated DNS query latency or timeouts reported by Kubernetes workloads dependent on the resolver.

Detection Strategies

  • Inspect HTTP request logs at ingress controllers and load balancers for GET /dns-query requests where the dns= parameter exceeds expected DNS message sizes.
  • Alert when CoreDNS pod resource consumption deviates from baseline, correlated with DoH request rate.
  • Use web application firewall rules to flag oversized query strings on DoH endpoints.

Monitoring Recommendations

  • Export CoreDNS Prometheus metrics and track coredns_dns_request_duration_seconds, process_resident_memory_bytes, and request counts per protocol.
  • Forward ingress and CoreDNS logs into a centralized analytics platform for correlation across CPU, memory, and request-size dimensions.
  • Configure rate-limiting and request-size thresholds on upstream proxies fronting the DoH endpoint.

How to Mitigate CVE-2026-32936

Immediate Actions Required

  • Upgrade CoreDNS to version 1.14.3 or later, which adds bounded reads to the DoH GET path.
  • Inventory all CoreDNS deployments, including those embedded in Kubernetes distributions, service meshes, and cloud-managed offerings, and confirm the running version.
  • Restrict exposure of the DoH endpoint to trusted networks where operationally feasible.

Patch Information

The issue is fixed in CoreDNS 1.14.3. Release notes and upgrade guidance are available in the CoreDNS Release v1.14.3 announcement. Kubernetes operators should validate compatibility with their cluster version before rolling the update across production nodes.

Workarounds

  • Disable the DoH server in the CoreDNS Corefile if DNS-over-HTTPS is not required.
  • Place a reverse proxy or WAF in front of CoreDNS that enforces a maximum URL length and query-parameter size on /dns-query requests.
  • Apply network-level rate limiting on the DoH endpoint to constrain request volume from any single source.
bash
# Example NGINX rule to bound DoH GET request size before reaching CoreDNS
location /dns-query {
    if ($request_method = GET) {
        set $doh_param_len ${#arg_dns};
        if ($doh_param_len > 8192) { return 414; }
    }
    client_max_body_size 65536;
    proxy_pass https://coredns_upstream;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeDOS

  • Vendor/TechCoredns

  • SeverityHIGH

  • CVSS Score8.7

  • EPSS Probability0.10%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityNone
  • AvailabilityHigh
  • CWE References
  • CWE-400
  • Technical References
  • CoreDNS Release v1.14.3

  • GitHub Security Advisory GHSA-63cw-r7xf-jmwr
  • Related CVEs
  • CVE-2026-32934: CoreDNS DNS-over-QUIC DoS Vulnerability

  • CVE-2026-26018: CoreDNS Denial of Service Vulnerability

  • CVE-2025-68151: CoreDNS Server DoS Vulnerability

  • CVE-2025-47950: CoreDNS DNS-over-QUIC DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English