Back

HIGH

CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison

Published May 5, 2026

Description

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The longestMatch() function in plugin/transfer/transfer.go uses a lexicographic string comparison instead of an actual longest-suffix match to select the winning zone. As a result, a permissive parent-zone transfer rule can override a restrictive subzone rule depending on zone name ordering (e.g., "example.org." > "a.example.org." lexicographically). This allows an unauthorized remote client to perform AXFR/IXFR for the subzone and retrieve its full zone contents. This issue has been fixed in version 1.14.3.

Affected products

Remediation

Red Hat mitigation

To mitigate this vulnerability, ensure that the CoreDNS `transfer` plugin is configured with explicit and precise Access Control List (ACL) rules for all zones and subzones. Avoid broad parent-zone transfer rules that could inadvertently override more restrictive subzone configurations. If zone transfers are not required, disable the `transfer` plugin or restrict its access to only trusted internal networks using firewall rules or CoreDNS configuration directives. Always review and validate `transfer` plugin configurations to prevent unintended information disclosure.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 5, 2026
Updated May 5, 2026
Reserved Mar 20, 2026
CISA Vulnrichment
Updated May 5, 2026
NVD
Status Analyzed
Modified Jul 24, 2026
Red Hat
Severity Moderate
Public date May 5, 2026
ENISA EUVD
Assigner GitHub_M
Published May 5, 2026
Updated May 5, 2026
Exploited since n/a
EUVD-2026-27450 GHSA-H8MM-C463-WJQ3