CVE-2026-24029

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.
Configurations

No configuration.

History

31 Mar 2026, 14:16

Type Values Removed Values Added
CWE CWE-863

31 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-31 12:16

Updated : 2026-04-01 14:24


NVD link : CVE-2026-24029

Mitre link : CVE-2026-24029

CVE.ORG link : CVE-2026-24029


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization