CVE-2026-19538: Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
Published Aug 26, 2026
·Updated
The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 4.15.1
Event History
Aug 26, 2026
CVE Published
via MITRE·08:47 AM
Data Sourced
via MITRE·08:47 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
What conditions are required to exploit this issue?
An attacker must be able to connect to the proxy protocol port over TCP or TLS, keep the connection open, and send the same query twice on that connection.
2
Which access controls are bypassed?
BLOCKED ACL items evaluated on the proxy protocol port to deny access can be bypassed completely under the affected TCP or TLS connection behavior.