SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19401

HIGH · CVSS 7.5 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A vulnerability exists in certain NSD server configurations that allows a remote client to crash the server's child processes by sending a specially crafted message with a specific number of DNS Cookie options. This can lead to significant service disruption, potentially denying DNS services to users. Organizations utilizing debugging or non-release builds of NSD should prioritize addressing this issue to maintain service availability and security.

CVE
CVE-2026-19401
Severity
HIGH
CVSS
7.5
EPSS
0.36%

Original NVD Description

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the serve childs, the remote client can severely hamper or, when positioned sufficiently close, deny all DNS service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)