The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
History

Tue, 01 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Nlnetlabs
Nlnetlabs nsd
Vendors & Products Nlnetlabs
Nlnetlabs nsd

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
Title Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
Weaknesses CWE-290
CWE-672
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NLnet Labs

Published:

Updated: 2026-08-26T14:00:12.918Z

Reserved: 2026-08-11T10:27:22.294Z

Link: CVE-2026-19538

cve-icon Vulnrichment

Updated: 2026-08-26T14:00:08.820Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-26T09:16:46.057

Modified: 2026-09-01T21:03:04.987

Link: CVE-2026-19538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:24:23Z