CVE-2026-19538
8.2
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Summary
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | NSD | 4.8.0 < 4.15.1 | affected |
Weaknesses
- CWE-290: CWE-290 Authentication Bypass by Spoofing
- CWE-672: CWE-672 Operation on a Resource after Expiration or Release
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.