{"id":"CVE-2026-18916","title":"Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query","summary":"Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-191"],"vendor":"nlnetlabs","product":"nsd","affected":["nsd >= 3.2.11, < 4.15.1"],"patched":["nsd 4.15.1"],"published":"2026-08-26","updated":"2026-09-08","sourceUpdated":"2026-09-08T20:00:51.850","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-18916","references":[{"url":"https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt","label":"sep@nlnetlabs.nl"}],"tags":["nvd"],"epss":0.00357,"epssPercentile":0.29552,"ingestedAt":"2026-09-08T20:10:03.158Z","slug":"CVE-2026-18916","body":"## Overview\n\nAny remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.\n\n## Affected\n\n- `nsd >= 3.2.11, < 4.15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nsd 4.15.1`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}