Last updated 29 June 2026
Several vulnerabilities were found in NSD. The overview of the vulnerabilities with a brief description is:
CVE-2026-18664 - severity: HIGH Wrong interpretation of ACL ranges
CVE-2026-18916 - severity: MEDIUM Remote TCP DoS by throttling the TCP receive window
CVE-2026-19401 - severity: HIGH Remote UDP DoS by sending multiple DNS Cookie options
CVE-2026-19538 - severity: HIGH Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
The patches are tested to apply/work on 4.15.0.
Best regards, -- Willem, on behalf of the NSD team.