Description
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
Published: 2026-08-26
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows a client to bypass all BLOCKED access control list items that would normally deny access when using the proxy protocol port over TCP or TLS. By keeping the connection open and sending the same query twice, an attacker can cause the evaluation to skip the blocking rules, effectively gaining access that should have been denied. This flaw is a direct control-bypass weakness and can lead to unauthorized data exposure or functionality access.

Affected Systems

The issue affects NLnet Labs NSD before version 4.15.1. All releases newer than 4.15.1 contain the fix. Users running older versions should update to the patched release to remove the vulnerability.

Risk and Exploitability

The CVSS score of 8.2 indicates a high severity impact. The EPSS score is not available, but the lack of a KEV listing suggests that there are no widely known exploits yet. The attack can be performed remotely over an open TCP or TLS connection to the proxy protocol port, especially when the connection is reused for multiple queries. Operators should assume the flaw could be exploited in the wild until the software is patched.

Generated by OpenCVE AI on August 26, 2026 at 10:25 UTC.

Remediation

Vendor Solution

This issue is fixed in 4.15.1 and all later versions.


OpenCVE Recommended Actions

  • Upgrade NSD to version 4.15.1 or later
  • If an upgrade cannot be applied immediately, temporarily disable or block traffic to the proxy protocol port until the patch is applied
  • Monitor network traffic and logs for repeated queries on the proxy port that could indicate exploitation attempts

Generated by OpenCVE AI on August 26, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Description The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
Title Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
Weaknesses CWE-290
CWE-672
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NLnet Labs

Published:

Updated: 2026-08-26T14:00:12.918Z

Reserved: 2026-08-11T10:27:22.294Z

Link: CVE-2026-19538

cve-icon Vulnrichment

Updated: 2026-08-26T14:00:08.820Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T10:30:04Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-672

    Operation on a Resource after Expiration or Release