CVE-2025-68151 (CNNVD-202601-1449)
中文标题:
CoreDNS 安全漏洞
英文标题:
CoreDNS gRPC/HTTPS/HTTP3 servers lack resource limits, enabling DoS via unbounded connections and oversized messages
漏洞描述
中文描述:
CoreDNS是CoreDNS社区的一个 DNS 服务器。 CoreDNS 1.14.0之前版本存在安全漏洞,该漏洞源于缺少资源限制控制,可能导致内存耗尽和服务崩溃。
英文描述:
CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTTPS, and HTTP/3) lack critical resource-limiting controls. An unauthenticated remote attacker can exhaust memory and degrade or crash the server by opening many concurrent connections, streams, or sending oversized request bodies. The issue is similar in nature to CVE-2025-47950 (QUIC DoS) but affects additional server types that do not enforce connection limits, stream limits, or message size constraints. Version 1.14.0 contains a patch.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| coredns | coredns | < 1.14.0 | - | - |
cpe:2.3:a:coredns:coredns:<_1.14.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
4.0 (cna)
MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2025-68151 |
2026-01-09 02:02:08 | 2026-01-12 02:12:28 |
| NVD | nvd_CVE-2025-68151 |
2026-01-09 03:00:10 | 2026-01-12 02:28:10 |
| CNNVD | cnnvd_CNNVD-202601-1449 |
2026-01-11 06:15:11 | 2026-01-12 02:38:14 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 其他
- cnnvd_id: 未提取 -> CNNVD-202601-1449
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- data_sources: ['cve'] -> ['cve', 'nvd']