When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.
References
Configurations
No configuration.
History
31 Mar 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-863 |
31 Mar 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 12:16
Updated : 2026-04-01 14:24
NVD link : CVE-2026-24029
Mitre link : CVE-2026-24029
CVE.ORG link : CVE-2026-24029
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
