PatchSiren cyber security CVE debrief
CVE-2026-18916 NLnet Labs CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T09:16:45.597Z and has not been modified since then. CVE-2026-18916 is a denial of service vulnerability in NSD instances. Remote clients can crash NSD serve children by throttling the TCP receive window after a TCP query, potentially leading to denial of all TCP service. The CVSS score of 6.9 indicates a medium severity level. Organizations should be aware of this potential vulnerability and take steps to inventory exposures, monitor for abnormal TCP receive window behavior, and apply remediation if available. This vulnerability requires specific conditions to be exploited, but could have significant impact if successfully exploited. Further analysis is needed to fully understand the affected scope, including potential variations in NSD instance configurations and network environments.
- Vendor
- NLnet Labs
- Product
- NSD
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-26
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-08-26
- Advisory updated
- 2026-09-01
Who should care
Organizations using NSD instances should be aware of this potential denial of service vulnerability and take steps to inventory exposures across their managed environments, monitor for abnormal TCP receive window behavior indicative of potential exploitation attempts, and apply remediation if available. Security teams should prioritize review of affected scope within their organizations, focusing on critical services that could be impacted by denial of service conditions.
Technical summary
CVE-2026-18916 allows remote clients to crash NSD serve children by throttling the TCP receive window after a TCP query. Continuous crashing can lead to denial of all TCP service to the NSD instance. CVSS score of 6.9 (MEDIUM) indicates significant impact but requires specific conditions.
Defensive priority
Medium-priority defensive actions recommended due to potential for denial of service via remote client throttling of TCP receive window.
Recommended defensive actions
- Inventory NSD instances for potential exposure
- Implement monitoring for abnormal TCP receive window behavior
- Review and apply vendor remediation if available
- Consider compensating controls for critical services
Evidence notes
Evidence from official CVE Program record and NIST NVD detail page indicates potential for remote denial of service via TCP receive window throttling. Further analysis needed to fully understand affected scope, including potential variations in NSD instance configurations and network environments. Defenders should verify exposure in their specific contexts, review vendor guidance for remediation steps, and consider compensating controls for critical services.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-18916 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-18916
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-18916 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18916
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.