CVE-2026-33489: CoreDNS' transfer stanza selection uses lexicographic compare (subzone ACL bypass)
(updated )
CoreDNS’ transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. A permissive parent-zone transfer rule can override a restrictive subzone rule (name-dependent), allowing an unauthorized client to perform AXFR/IXFR for the subzone and retrieve its zone contents.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-33489 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →