PT-2026-35877 · Coredns+1 · Coredns+1

·

CVE-2026-33489

·

Published

2026-04-28

·

Updated

2026-07-30

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CoreDNS versions prior to 1.14.3
Description The transfer plugin in CoreDNS can select an incorrect Access Control List (ACL) stanza when both a parent zone and a more-specific subzone are configured. This occurs because the longestMatch() function in plugin/transfer/transfer.go employs a lexicographic string comparison rather than a true longest-suffix match to determine the winning zone. Consequently, a permissive transfer rule for a parent zone may override a restrictive rule for a subzone depending on the alphabetical ordering of the zone names. This flaw allows an unauthorized remote client to perform AXFR or IXFR (zone transfer protocols used to replicate DNS databases) for the subzone and retrieve its complete zone contents.
Recommendations Update CoreDNS to version 1.14.3 or later.

Exploit

Fix

DoS

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-85721
BDU:2026-12027
CLEANSTART-2026-SL86558
CLEANSTART-2026-VJ54611
CVE-2026-33489
GHSA-H8MM-C463-WJQ3
GO-2026-5417
OPENSUSE-SU-2026:20703-1
OPENSUSE-SU-2026:21483-1

Affected Products

Coredns
Red Os