
CVE-2026-33376 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, a… https://www.cve.org/CVERecord?id=CVE-2026-33376
Post summary
The disclosure details how the Auth Proxy IPv6 allow‑list defaults to /32 addresses, making it vulnerable unless an explicit mask is set. No exploit, PoC, or patch information is provided.
