CVE-2026-19538Disclosure(nlnetlabs / nsd)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290CWE-672

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsd

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-08-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
nsd

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-26: 2Mentions · 2026-08-27: 1Mentions · 2026-08-30: 1Technical Details · 2026-08-26: 208-2608-2708-30
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-262
Disclosure2
2026-08-271
Disclosure1
2026-08-301
General1
Full discourse4 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【注意喚起】NSDの脆弱性情報が公開されました(CVE-2026-18664、CVE-2026-18916、CVE-2026-19401、CVE-2026-19538) https://jprs.jp/tech/security/2026-08-27-nsd.html

    Post summary

    JPRS has published vulnerability information for multiple CVEs related to NSD, but the notice contains no technical details, PoC, or exploitation evidence.

    01130853
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19538 The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and … https://www.cve.org/CVERecord?id=CVE-2026-19538

    Post summary

    The article discloses CVE‑2026‑19538, noting that ACL blocks on the proxy protocol port can be bypassed via TCP/TLS connections.

    000201.2K
    58.1K followersView on X
  • 珈琲好き@likecoffee
    General

    NSDの脆弱性情報が公開されました (CVE-2026-18664、CVE-2026-18916、CVE-2026-19401、CVE-2026-19538) https://jprs.jp/tech/security/2026-08-27-nsd.html #%E6%8A%80%E8%A1%93%E7%B3%BB-%E8%B3%87%E6%96%99 #feedly

    Post summary

    NSD vulnerability information for CVE-2026-18664, CVE-2026-18916, CVE-2026-19401, and CVE-2026-19538 has been published, but no PoC, exploit, patch, or technical details are provided in this text.

    0000059
    1.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19538 The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and … https://www.cve.org/CVERecord?id=CVE-2026-19538 ----- Traducción: CVE-2026-19538 Los… https://infoflow.cloud`

    Post summary

    The post announces CVE-2026-19538 and highlights that access‑control list items on the proxy protocol port can be bypassed over TCP/TLS, but offers no proof‑of‑concept, exploit tool, or mitigation information.

    0000027
    102 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsnsd---

Explore more