CVE-2026-33489: CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
Summary CoreDNS' transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. A permissive parent-zone transfer rule can override a restrictive subzone rule (name-dependent), allowing an unauthorized client to perform AXFR/IXFR for the subzone and retrieve its zone contents.
Details In plugin/transfer/transfer.go, stanza selection is implemented by longestMatch(), which is documented as "longest zone match wins", but it actually chooses the winner via a lexicographic string comparison: - zone := "" // longest zone match wins (plugin/transfer/transfer.go) - if z > zone { zone = z; x = xfr } (plugin/transfer/transfer.go)
So, a parent zone like example.org. can beat a child zone like a.example.org. purely due to lexicographic ordering ("example.org." > "a.example.org."), even though the child zone is the longer/more specific suffix match. The bypass is data-dependent (some child labels will win, some will lose), making it operationally non-intuitive.
PoC 1. Adjust COREDNSBIN in the PoC to point at right path (see the top-level const definitions for tunables as well) 2. Run python3 ./acl-repro.py 3. Expected output: Baseline (only subzone transfer rule) axfr a.example.org.: rcode=5 ancount=0 (expected REFUSED=5)
Candidate (add permissive parent transfer rule) axfr a.example.org.: rcode=0 ancount=5 (expected NOERROR=0 with ancount>0)
OK Subzone transfer ACL bypass reproduced: adding a permissive parent-zone stanza can override a stricter child-zone stanza due to lexicographic zone selection.
Impact Unauthorized zone transfer can expose full zone contents to a remote network client that was intended to be denied by a subzone-specific transfer policy.
Other sources
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.
— MITRE
CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
go/github.com/coredns/corednsto a version that resolves this vulnerability.Fixed in 1.14.3 - Upgrade
Upgrade
coredns/transferto a version that resolves this vulnerability.Fixed in 1.14.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-33489?
CVE-2026-33489 has been classified as a high-severity vulnerability due to its potential to allow unauthorized AXFR/IXFR transfers.
How do I fix CVE-2026-33489?
To mitigate CVE-2026-33489, upgrade CoreDNS to version 1.14.3 or later to address the ACL misconfiguration issue.
Who is affected by CVE-2026-33489?
CoreDNS users with parent and subzone configurations that have conflicting ACL rules are affected by CVE-2026-33489.
What does CVE-2026-33489 exploit?
CVE-2026-33489 exploits a misconfiguration in CoreDNS' transfer plugin that improperly selects ACL stanzas between parent and subzones.
Can CVE-2026-33489 lead to data exposure?
Yes, CVE-2026-33489 can lead to unauthorized access to zone transfers, potentially exposing sensitive DNS data.