Access Control Bypass Vulnerability in NSD by NLnet Labs
CVE-2026-19538
8.2HIGH
What is CVE-2026-19538?
An access control list vulnerability in the NSD DNS server allows an attacker to bypass security measures that deny access when connecting over TCP or TLS. This occurs specifically when a query is sent twice on a connection that is kept open, leading to unauthorized access to restricted resources. This vulnerability necessitates prompt remedial action to secure affected systems.
Affected Version(s)
NSD 4.8.0 < 4.15.1
