Nlnet · Nsd · CVE-2026-19401
**Name of the Vulnerable Software and Affected Versions**
NSD (affected versions not specified)
**Description**
A remote client can cause a crash of the NSD serve child process in debugging or non-release build types. This occurs when the process receives a specially crafted message containing a specific number of DNS Cookie options, such as 17 options when the UDP payload size is 512. Repeatedly crashing these processes can severely degrade performance or lead to a complete denial of DNS service.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.