alpine · CVE-2026-24029

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2026-24029: 1 source package rows (dnsdist); 12 state rows across 2 repos (3.23-community, edge-community); fixed 0, open 12.

Description:

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.

cvelogic Threat Intelligence