VYPR
Unrated severityNVD Advisory· Published May 25, 2026

Nord VPN 6.14.31 Denial of Service via Password Field

CVE-2018-25368

Description

Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Nord VPN 6.14.31 crashes when an unauthenticated attacker submits an excessively long password string, enabling denial of service.

Vulnerability

NordVPN version 6.14.31 and earlier contains a denial-of-service vulnerability in the password input field. The application fails to properly validate the length of the password string, leading to excessive memory allocation (CWE-789) when an attacker submits a buffer of repeated characters. This issue is reachable without authentication and affects the desktop client on Windows [1][2].

Exploitation

An attacker with local access to the machine can trigger the vulnerability by copying a long string (e.g., 100,000 A characters) from a file and pasting it into the password field of the NordVPN login dialog. When the user attempts to authenticate, the application crashes due to the oversized input. No special privileges or user interaction beyond pasting the string are required [2].

Impact

Successful exploitation causes the NordVPN application to crash, resulting in a denial of service. No data is disclosed, modified, or permanently lost; the application must be restarted to resume normal operation [1][2].

Mitigation

No official fix is documented in the available references. Users should ensure they are running the latest version of NordVPN and apply any updates from the vendor. As a workaround, avoid pasting untrusted or excessively long strings into the password field [1][2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.