Denial of Service Vulnerability in NSD Server by NLNet Labs
CVE-2026-19401
8.2HIGH
What is CVE-2026-19401?
A remote client can exploit a vulnerability in debugging or non-release builds of the NSD server by sending a specially crafted message that includes an exact number of DNS Cookie options (17 when the UDP payload is 512). By continuously sending these messages, the attacker can cause the NSD server's child processes to crash, significantly disrupting DNS services and potentially leading to denial of service for users. This vulnerability highlights the importance of securing DNS servers against targeted attacks aimed at their operational integrity.
Affected Version(s)
NSD 4.3.7 < 4.15.1
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Qifan Zhang from Palo Alto Networks
afldl <zhangph@yandex.com>
