PatchSiren cyber security CVE debrief
CVE-2026-19538 NLnet Labs CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T09:16:46.057Z and has not been modified since then. This vulnerability, CVE-2026-19538, involves BLOCKED access control list items on the proxy protocol port that can be bypassed when connecting over TCP or TLS and sending the query twice on a kept-open connection. The vulnerability has a high CVSS score of 8.2 and is classified as HIGH severity. Affected product deployments may be vulnerable to access control bypass, potentially allowing unauthorized access or malicious activity. Security teams and administrators responsible for proxy protocol port configurations and access control management should be aware of this vulnerability and take necessary defensive actions. Further verification is needed due to limited evidence, and defenders should verify configurations, monitor connection attempts, and prioritize patching or mitigation efforts for affected systems.
- Vendor
- NLnet Labs
- Product
- NSD
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-01
Who should care
Security teams and administrators responsible for proxy protocol port configurations and access control management should be aware of this vulnerability and take necessary defensive actions. Operators of affected systems, vulnerability management teams, and security personnel should prioritize patching or mitigation efforts and review compensating controls to minimize potential impact. Platform administrators and security teams may need to coordinate with vendors for patching or mitigation guidance specific to their environments.
Technical summary
The BLOCKED access control list items that are evaluated to deny access on the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on a connection that is kept open. This vulnerability has a high CVSS score of 8.2 and is classified as HIGH severity. Affected product deployments may be vulnerable to access control bypass, potentially allowing unauthorized access or malicious activity.
Defensive priority
High-priority defensive review recommended due to high CVSS score of 8.2 and potential for access control bypass.
Recommended defensive actions
- Review and verify access control configurations for proxy protocol port
- Implement compensating controls to monitor and restrict suspicious connection attempts
- Inventory affected systems and prioritize patching or mitigation efforts
Evidence notes
Evidence is limited; primary official records indicate access control list items can be bypassed when connecting over TCP or TLS and sending the query twice on a kept-open connection. Further verification needed. Limited evidence suggests that defenders should verify configurations, monitor connection attempts, and prioritize patching or mitigation efforts for affected systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19538 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19538
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19538 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19538
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.