Medium severity5.3NVD Advisory· Published Jul 15, 2026· Updated Jul 30, 2026
CVE-2026-47703
CVE-2026-47703
Description
AdGuard Home is a network-wide software for blocking ads and tracking. Prior to 0.107.75, AdGuard Home's client-triggered DoQ forwarding path to a udp:// upstream reduced backend UDP DNS state by producing dns_id=0 or txid=0 and exposed a quoted-port ICMP source-port oracle, weakening DNS response matching for forwarded queries. This issue is fixed in version 0.107.75.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/AdguardTeam/AdGuardHomeGo | < 0.107.75 | 0.107.75 |
github.com/AdguardTeam/dnsproxyGo | < 0.81.3 | 0.81.3 |
Affected products
3- Range: <0.107.75
- osv-coordsRange: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
5- github.com/AdguardTeam/AdGuardHome/security/advisories/GHSA-xgx4-4h9w-53pvnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-xgx4-4h9w-53pvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-47703ghsaADVISORY
- github.com/AdguardTeam/dnsproxy/commit/f00d992ce9567a50f596853978ad6500acfdcf1dghsaWEB
- pkg.go.dev/vuln/GO-2026-5756ghsaWEB
News mentions
0No linked articles in our index yet.