Improper access control in NSD - CVE-2026-19538

 

Improper access control in NSD - CVE-2026-19538

Published: August 26, 2026


Vulnerability identifier: #VU145739
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-19538
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass IP-based access controls.

The vulnerability exists due to improper access control in the proxy protocol port handling when processing a repeated query over a kept-open TCP or TLS connection. A remote user can send the same query twice on a persistent connection to bypass IP-based access controls.

This issue affects BLOCKED access control list items and may allow spoofing of arbitrary IP addresses for queries, transfers, and notifies.


Affected software

NSD
Fedora
nsd

How to mitigate CVE-2026-19538

Install security update from vendor's website.

NSD - update to 4.15.1
nsd - addressed in versions 4.15.1-1.el9, 4.15.1-1.el10_2, 4.15.1-1.el10_3, 4.15.1-1.el10_4, 4.15.1-1.fc43, 4.15.1-1.fc44, 4.15.1-1.fc45

External References

Related Security Bulletins