An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
References
Configurations
No configuration.
History
25 Jun 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-772 |
25 Jun 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-25 13:16
Updated : 2026-06-25 15:59
NVD link : CVE-2026-40209
Mitre link : CVE-2026-40209
CVE.ORG link : CVE-2026-40209
JSON object : View
Products Affected
No product.
CWE
CWE-772
Missing Release of Resource after Effective Lifetime
