Vulnerability Description
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Nsd | >= 3.2.11, < 4.15.1 |
Related Weaknesses (CWE)
References
- https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txtVendor Advisory
FAQ
What is CVE-2026-18916?
CVE-2026-18916 is a vulnerability with a CVSS score of 7.5 (HIGH). Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this N...
How severe is CVE-2026-18916?
CVE-2026-18916 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-18916?
Check the references section above for vendor advisories and patch information. Affected products include: Nlnetlabs Nsd.