PT-2026-81985 · Nlnet+4 · Nsd

·

CVE-2026-18664

·

Published

2026-08-26

·

Updated

2026-08-26

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions NSD (affected versions not specified)
Description On little-endian systems, the software incorrectly compares IP addresses with access control ranges. This occurs because IPv4 addresses are compared as unsigned 32-bit numbers using the host's endianness, while the comparison values remain in network byte order (big-endian). For IPv6 addresses, the process involves four separate unsigned 32-bit number comparisons, also failing to account for the difference between host endianness and network byte order. Consequently, IP addresses intended to be allowed may be denied, and those intended to be denied may be granted access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18664

Affected Products

Nsd