Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Netatalk — Vulnerabilities & Security Advisories 43

All 43 CVE vulnerabilities found in Netatalk, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of vulnerabilities affecting Netatalk, specifically focusing on the Common Weakness Enumeration (CWE) classification framework used to categorize software security flaws. It collects data regarding known security issues, configuration errors, and implementation flaws identified in the Netatalk open-source AppleTalk protocol stack and its AFP file server implementation, covering the historical period from its initial public releases through recent updates. By utilizing this resource, users can efficiently track vendor security advisories and patches as they are released, gain a deeper understanding of specific weakness classes such as buffer overflows or privilege escalation mechanisms inherent to the product, and examine the complete vulnerability history to assess long-term risk profiles and remediation timelines. This structured approach allows system administrators and security researchers to correlate specific weaknesses with distinct software versions, facilitating more informed decision-making regarding upgrade paths and mitigation strategies without relying on scattered or incomplete information sources. The content is organized to highlight the evolution of security concerns within the Netatalk ecosystem, ensuring that stakeholders have access to a centralized repository of technical details and contextual analysis. This enables proactive management of security posture by identifying patterns in reported issues and understanding the impact of known defects on network integrity and data confidentiality.

Vendor: Netatalk

CVE IDTitleCVSSSeverityPublished
CVE-2026-45698 Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir() CWE-191 7.5 High2026-08-17
CVE-2026-45699 Netatalk has Integer Underflow → Stack Buffer Overflow in copydir() CWE-191 7.5 High2026-08-14
CVE-2026-7837 TOCTOU with root privilege in ad_flush CWE-367 3.7 Low2026-05-21
CVE-2026-44075 Missing break in DSI OpenSession CWE-484 3.7 Low2026-05-21
CVE-2026-44074 Bitwise OR of errno values CWE-682 3.7 Low2026-05-21
CVE-2026-44071 FORTIFY_SOURCE disabled CWE-693 3.7 Low2026-05-21
CVE-2026-44057 Dead bounds check in Spotlight RPC unmarshaller CWE-561 3.1 Low2026-05-21
CVE-2026-7836 hextoint macro uppercase bug CWE-682 3.1 Low2026-05-21
CVE-2026-7835 Format string argument mismatch CWE-134 3.1 Low2026-05-21
CVE-2026-44076 Shell injection via volume path CWE-78 6.7 Medium2026-05-21
CVE-2026-44073 seteuid failure ignored in auth modules CWE-273 4.0 Medium2026-05-21
CVE-2026-44072 system() after failed chdir() CWE-78 2.5 Low2026-05-21
CVE-2026-44070 Unbounded realloc in charset conversion CWE-770 3.1 Low2026-05-21
CVE-2026-44069 Integer underflow in volxlate CWE-191 3.4 Low2026-05-21
CVE-2026-44068 EA path traversal via incomplete sanitization CWE-22 7.6 High2026-05-21
CVE-2026-44067 EA header parsing heap over-read CWE-125 3.7 Medium2026-05-21
CVE-2026-44066 Heap out-of-bounds reads in Spotlight RPC unmarshalling CWE-125 7.1 High2026-05-21
CVE-2026-44065 Off-by-two in papd lp_write() CWE-193 3.7 Medium2026-05-21
CVE-2026-44064 ASP session ID out-of-bounds access CWE-125 7.1 High2026-05-21
CVE-2026-44063 LDAP filter injection CWE-90 4.2 Medium2026-05-21
CVE-2026-44062 Missing o_len bounds check in pull_charset_flags() CWE-787 7.5 High2026-05-21
CVE-2026-44061 DES-ECB auth with timing side channel CWE-208 5.9 Medium2026-05-21
CVE-2026-44060 Integer underflow in dsi_writeinit() leads to denial of service CWE-191 7.5 High2026-05-21
CVE-2026-44059 Non-reentrant privilege toggle CWE-362 3.9 Medium2026-05-21
CVE-2026-44058 Authentication bypass via admin auth user CWE-287 6.4 High2026-05-21
CVE-2026-44056 Stack buffer overflow in desktop.c CWE-121 6.0 Medium2026-05-21
CVE-2026-44055 Bitwise OR logic bug enables shell injection CWE-78 7.5 High2026-05-21
CVE-2026-44054 Predictable afpd session token CWE-330 6.5 Medium2026-05-21
CVE-2026-44053 Weak cryptography in DHCAST128 UAM CWE-327 7.4 High2026-05-21
CVE-2026-44052 LDAP simple-bind password exposure in log output CWE-532 7.5 High2026-05-21

All 43 known CVE vulnerabilities affecting Netatalk with full Chinese analysis, references, and POCs where available.