CVE-2026-40209
MEDIUM
NVD
CVSS Score
5.3
Severity
MEDIUM
Published
Jun 25, 2026
Vendor
unknown
Description
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.