CVE-2026-47703 MEDIUM

CVE-2026-47703: AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle

Vendor Adguardteam
Product AdGuardHome
Weakness CWE-330 · Insufficient randomness
Published July 15, 2026
Last update July 15, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for forwarded queries. This issue is fixed in version 0.107.75.

Key dates

02Disclosure timeline

July 15, 2026 CVE published
July 15, 2026 Record updated

Related vulnerabilities

04Related CVE