๐Ÿ” CVE Alert

CVE-2026-19401

UNKNOWN 0.0

Remote UDP DoS by sending multiple DNS Cookie options

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can severely hamper or, when positioned sufficiently close, deny all DNS service.

CWE CWE-617 CWE-400
Vendor nlnet labs
Product nsd
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for nlnet labs nsd

Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

NLnet Labs / NSD
4.3.7 < 4.15.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nlnetlabs.nl: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt

Credits

Qifan Zhang from Palo Alto Networks afldl <[email protected]>