CVE-2026-18916
Remote TCP DoS by throttling the TCP receive window
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.
| CWE | CWE-191 |
| Vendor | nlnet labs |
| Product | nsd |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for nlnet labs nsd
Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
NLnet Labs / NSD
3.2.11 < 4.15.1
References
Credits
Akhil Koul (https://github.com/akoul)