Dear all.
NSD 4.15.1 is available:
https://nlnetlabs.nl/downloads/nsd/nsd-4.15.1.tar.gz
sha256 ce41e13317d35d7a5b3f34605487429391a41eca77b2006edd11e9453432c609
pgp https://nlnetlabs.nl/downloads/nsd/nsd-4.15.1.tar.gz.asc
The release is signed with the OpenPGP software signing key that is in use since Jan 1st 2026:
User ID: NLnet Labs releases signing key G2 <releases@nlnetlabs.nl>
Key ID: A144 323D EAAC DF45
Fingerprint: 2310 1869 0C4D 903E F419 146A A144 323D EAAC DF45
The key is available from NLnet Labs - Software Signing Keys
BUG FIXES:
- Fix for CVE-2026-18664: IP range access control restrictions are bypassed for some unintended IP.
Thanks to Qifan Zhang, Palo Alto Networks for the report
Thanks to Claude and Ada Logics for the report
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18664.txt - Fix for CVE-2026-18916: Any remote client can denial TCP service by throttling the TCP receive window (down to 1).
Thanks to Akhil Koul (akoul (Akhil Koul) · GitHub) for the report
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-18916.txt - Fix for CVE-2026-19401: Any remote client can denial UDP service by sending a specifically crafted query with multiple DNS Cookie options.
Thanks to Qifan Zhang, Palo Alto Networks for the report
Thanks to afldl zhangph@yandex.com for the report
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19401.txt - Fix for CVE-2026-19538: Anyone with access to the proxy protocol port over TCP or TLS can bypass BLOCKED access control items.
Thanks to Qifan Zhang, Palo Alto Networks for the report
https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-19538.txt