PatchSiren

Nordvpn CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Nordvpn CVE published 2026-05-25

CVE-2018-25368

CVE-2018-25368 describes a denial-of-service vulnerability in Nord VPN 6.14.31 where unauthenticated attackers can crash the application by submitting an excessively long string in the password field. The vulnerability is triggered when attackers paste a buffer of repeated characters into the password input field during authentication attempts. The CVSS 4.0 vector indicates network attack vector with low [truncated]