{"id":"CVE-2026-18916","details":"Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.","modified":"2026-09-10T08:07:44.364130Z","published":"2026-08-26T09:16:45.597Z","references":[{"type":"ADVISORY","url":"https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nlnetlabs/nsd","events":[{"introduced":"954b5a21908dbb621f8bedd0d5f834d4cd680028"},{"fixed":"a06e6ce15b11a18b2c7eddbf3a8053696c7fd28e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.2.11"},{"fixed":"4.15.1"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-18916.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}