Junglewise Threat Intelligence

CVE-2026-19401: NLnetLabs NSD denial of service via crafted DNS Cookie options

CVE-2026-19401 · Severity: high · CVSS 7.5 · Published 2026-08-26

Technologies: Nlnetlabs Nsd. Vendors: Nlnetlabs.

Executive brief

NSD is an open-source authoritative DNS server used by organizations to host DNS zones. A remote attacker can crash NSD server processes by sending specially crafted DNS queries containing multiple DNS Cookie options, leading to denial of DNS service. By repeatedly sending such queries, attackers can severely degrade or completely disable DNS resolution for affected organizations.

Technical details

This is a denial-of-service vulnerability triggered by improper handling of DNS Cookie EDNS options. An unauthenticated remote attacker can send a crafted DNS query with a specially tuned number of DNS Cookie options (e.g., 17 when UDP payload size is 512) to crash NSD child processes, particularly in debug/non-release builds. The vulnerability is triggered over the network without authentication or user interaction. By continuously sending such queries, an attacker positioned close to the target can severely hamper or deny all DNS service. NSD versions 4.3.7 through 4.15.0 are affected; version 4.15.1 includes a patch, and a manual patch is available for 4.15.0.

Affected products

  • NLnetLabs NSD 4.3.7 through 4.15.0

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Version 4.15.1 released with patch

References

Related threats