CVE-2026-19401
Remote UDP DoS by sending multiple DNS Cookie options
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can severely hamper or, when positioned sufficiently close, deny all DNS service.
| CWE | CWE-617 CWE-400 |
| Vendor | nlnet labs |
| Product | nsd |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for nlnet labs nsd
Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
NLnet Labs / NSD
4.3.7 < 4.15.1
References
Credits
Qifan Zhang from Palo Alto Networks afldl <[email protected]>