Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 25 May 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate. | |
| Title | Nord VPN 6.14.31 Denial of Service via Password Field | |
| First Time appeared |
Nordvpn
Nordvpn nordvpn |
|
| Weaknesses | CWE-789 | |
| CPEs | cpe:2.3:a:nordvpn:nordvpn:*:*:*:*:*:macos:*:* | |
| Vendors & Products |
Nordvpn
Nordvpn nordvpn |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-25T14:15:13.971Z
Reserved: 2026-05-25T13:35:56.999Z
Link: CVE-2018-25368
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses