CVE-2026-19401

Source
https://cve.org/CVERecord?id=CVE-2026-19401
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19401.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-19401
Downstream
Published
2026-08-26T09:16:45Z
Modified
2026-09-10T08:07:43Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can severely hamper or, when positioned sufficiently close, deny all DNS service.

References

Affected packages

Git / github.com/nlnetlabs/nsd

Affected ranges

Type
GIT
Repo
https://github.com/nlnetlabs/nsd
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "4.3.7"
        },
        {
            "fixed": "4.15.1"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

Other
NSD_4_10_0_RC1
NSD_4_10_1_RC1
NSD_4_10_1_RC2
NSD_4_10_1_REL
NSD_4_11_0_RC1
NSD_4_11_0_REL
NSD_4_11_1_REL
NSD_4_12_0_RC1
NSD_4_12_0_REL
NSD_4_13_0_RC1
NSD_4_13_0_REL
NSD_4_14_0_RC1
NSD_4_14_1_RC1
NSD_4_14_1_REL
NSD_4_14_2_RC1
NSD_4_14_2_REL
NSD_4_15_0_RC1
NSD_4_15_0_REL
NSD_4_3_7_REL
NSD_4_3_8_RC1
NSD_4_3_8_RC2
NSD_4_3_8_REL
NSD_4_3_9_RC1
NSD_4_3_9_REL
NSD_4_4_0_RC1
NSD_4_4_0_REL
NSD_4_5_0_RC1
NSD_4_5_0_REL
NSD_4_6_0_RC1
NSD_4_6_0_REL
NSD_4_6_1_RC1
NSD_4_6_1_REL
NSD_4_7_0_RC1
NSD_4_7_0_REL
NSD_4_8_0_RC1
NSD_4_8_0_REL
NSD_4_9_0_RC1
list

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-19401.json"