Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33489

Опубликовано: 05 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.

A flaw was found in CoreDNS. An unauthorized remote client can exploit a vulnerability in the transfer plugin's Access Control List (ACL) stanza selection. This occurs when both a parent zone and a more-specific subzone are configured, and the longestMatch() function incorrectly uses a lexicographic string comparison. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule, allowing the client to perform zone transfers (AXFR/IXFR) for the subzone and retrieve its full zone contents. This leads to the disclosure of sensitive information.

Меры по смягчению последствий

To mitigate this vulnerability, ensure that the CoreDNS transfer plugin is configured with explicit and precise Access Control List (ACL) rules for all zones and subzones. Avoid broad parent-zone transfer rules that could inadvertently override more restrictive subzone configurations. If zone transfers are not required, disable the transfer plugin or restrict its access to only trusted internal networks using firewall rules or CoreDNS configuration directives. Always review and validate transfer plugin configurations to prevent unintended information disclosure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-agent-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/lighthouse-coredns-rhel9Fix deferred
Red Hat OpenShift Container Platform 4openshift4/ose-coredns-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1025
https://bugzilla.redhat.com/show_bug.cgi?id=2466859CoreDNS: github.com/coredns/coredns: CoreDNS: Information disclosure via incorrect ACL stanza selection in transfer plugin

EPSS

Процентиль: 32%
0.00388
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.

msrc
3 месяца назад

CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison

CVSS3: 7.5
debian
3 месяца назад

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14 ...

CVSS3: 7.5
redos
10 дней назад

Уязвимость coredns

CVSS3: 7.5
github
3 месяца назад

CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)

EPSS

Процентиль: 32%
0.00388
Низкий

6.5 Medium

CVSS3