Security Advisory

CVE-2026-40209

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-25 12:23:05
Last updated 2026-06-25 13:56:22
Assigner OX
CVSS score 5.3
State PUBLISHED

Description

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.