CVE-2026-19538
CVE-2026-19538 is a high-severity vulnerability in Nlnetlabs Nsd with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-290.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- CVSS v4: 8.2
- EPSS exploit prediction: 0% (13th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-290
- Affected product: Nlnetlabs Nsd
- Published:
- Last modified:
Description
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
Frequently asked questions
- What is CVE-2026-19538?
- The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
- How severe is CVE-2026-19538?
- CVE-2026-19538 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity high, and availability none.
- Is CVE-2026-19538 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (13th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-19538?
- CVE-2026-19538 affects Nlnetlabs Nsd. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-19538?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-19538 published?
- CVE-2026-19538 was published on 2026-08-26 and last updated on 2026-09-08.
References
Affected products (1)
- cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:*
More vulnerabilities in Nlnetlabs Nsd
- CVE-2026-18664 — Critical (CVSS 9.1): When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP…
- CVE-2026-12244 — High (CVSS 8.8): If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS…
- CVE-2026-12246 — High (CVSS 8.1): NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the…
- CVE-2026-19401 — High (CVSS 7.5): Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted…
- CVE-2026-18916 — High (CVSS 7.5): Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously…
- CVE-2026-12490 — High (CVSS 7.5): When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate…
All CVEs affecting Nlnetlabs Nsd →
Other CWE-290 vulnerabilities
- CVE-2026-69843 — Critical (CVSS 10.0): Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-76423 — Critical (CVSS 10.0): A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain…
- CVE-2026-54782 — Critical (CVSS 10.0): CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,…
- CVE-2026-48567 — Critical (CVSS 10.0): Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a…
- CVE-2026-6213 — Critical (CVSS 10.0): A vulnerability in Remote Spark SparkView before build 1122 allows an attacker to bypasses the local connection check…
- CVE-2026-39858 — Critical (CVSS 10.0): Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high…