CVE-2026-19538CWE-290CWE-672
CVE-2026-19538
published August 26, 2026
What it is
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
The record
Technical detail
- CVSS
- 8.2 · NONE
- CVSS v4.0
- 8.2 · CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00354 · 28.4th percentile
- Weaknesses
- CWE-290 · Authentication Bypass by Spoofing; CWE-672 · Operation on a Resource after Expiration or Release
- Published
- 2026-08-26T13:16Z
References (1)
EPSS history
Timeline