Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
This issue is fixed in 4.15.1 and all later versions.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt |
|
History
Wed, 26 Aug 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance. | |
| Title | Remote TCP DoS by throttling the TCP receive window | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-08-26T08:39:12.258Z
Reserved: 2026-08-05T07:36:55.457Z
Link: CVE-2026-18916
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-26T09:30:04Z
Weaknesses