Improper access control in CoreDNS - CVE-2026-33489
Published: April 25, 2026
CoreDNS
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the transfer plugin stanza selection logic when processing AXFR or IXFR requests for a configured subzone. A remote attacker can send a zone transfer request to disclose sensitive information.
Exploitation is possible when both a parent zone and a more-specific subzone are configured and a permissive parent-zone transfer rule overrides a restrictive subzone rule due to lexicographic zone selection.