← back
CVE-2026-19538highCWE-290CWE-672

Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.2epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Affected products
NLnet Labs · NSD