
CVE-2026-24029 When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skippe… https://www.cve.org/CVERecord?id=CVE-2026-24029
Post summary
The post announces CVE‑2026‑24029, detailing that turning off the `early_acl_drop` option on a DNS over HTTPS frontend bypasses ACL checks, potentially creating a security loophole.
