๐Ÿ” CVE Alert

CVE-2026-33489

UNKNOWN 0.0

CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.

CWE CWE-863
Vendor coredns
Product coredns
Published May 5, 2026
Last Updated May 5, 2026
Stay Ahead of the Next One

Get instant alerts for coredns coredns

Be the first to know when new unknown vulnerabilities affecting coredns coredns are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

coredns / coredns
< 1.14.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/coredns/coredns/security/advisories/GHSA-h8mm-c463-wjq3 github.com: https://github.com/coredns/coredns/releases/tag/v1.14.3