CVE-2026-19538CWE-290CWE-672

CVE-2026-19538

published August 26, 2026

CVSS
8.2
EPSS
0%
Percentile
28.4
In the wild
Unconfirmed
What it is

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

The record
Technical detail
CVSS
8.2 · NONE
CVSS v4.0
8.2 · CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00354 · 28.4th percentile
Weaknesses
CWE-290 · Authentication Bypass by Spoofing; CWE-672 · Operation on a Resource after Expiration or Release
Published
2026-08-26T13:16Z
References (1)
EPSS history
Timeline
  • 27 AUG 06:20Z
    EPSS moved — → 0%
    epss
  • 26 AUG 08:47Z
    Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
    cvelistv5