CVE-2018-25368High· 7.5▾ TwilightNord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated character…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-106452Medium· 5.3yawkat LZ4 Java provides LZ4 compression for Java
CVE-2026-103005Medium· 6.5Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Allocation (CAPEC-130)
CVE-2026-106453Medium· 5.3yawkat LZ4 Java provides LZ4 compression for Java
CVE-2026-106114Medium· 5.3ImageSharp is a 2D graphics library
CVE-2026-77050Medium· 5.3An issue was discovered in Django 6.1 before 6.1.2, 6.0 before 6.0.9, and 5.2 before 5.2.18. `django.utils.translation.get_supported_language_variant()` is subject to a potential denial-of-service attack when processing many distinct, v…
CVE-2026-105749Medium· 6.5Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem