CVE-2018-25368: Nordvpn

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.

Affected products

  • Nordvpn Nordvpn: up to and including 6.14.31

Published 2026-05-25. Last modified 2026-10-06.