Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Netatalk — Vulnerabilities & Security Advisories 43

Browse all 43 CVE security advisories affecting Netatalk. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netatalk serves as an open-source implementation of the Apple Filing Protocol (AFP), enabling file sharing between Unix-like systems and macOS devices. Historically, it has been susceptible to remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from improper input validation and insecure default configurations. The software's 8 recorded CVEs highlight persistent security concerns, with several critical flaws allowing unauthenticated attackers to execute arbitrary commands or gain elevated access. While no major public incidents have been widely documented, the consistent discovery of vulnerabilities underscores the importance of regular updates and hardening for production deployments.

Found 43 results / 43 Clear Filters
Top products by Netatalk: Netatalk
CVE ID Title CVSS Severity Published
CVE-2026-45698 Netatalk has Integer Underflow → Stack Buffer Overflow in deletedir() — netatalk CWE-191 7.5 High 2026-08-17
CVE-2026-45699 Netatalk has Integer Underflow → Stack Buffer Overflow in copydir() — netatalk CWE-191 7.5 High 2026-08-14
CVE-2026-7837 TOCTOU with root privilege in ad_flush — Netatalk CWE-367 3.7 Low 2026-05-21
CVE-2026-44075 Missing break in DSI OpenSession — Netatalk CWE-484 3.7 Low 2026-05-21
CVE-2026-44074 Bitwise OR of errno values — Netatalk CWE-682 3.7 Low 2026-05-21
CVE-2026-44071 FORTIFY_SOURCE disabled — Netatalk CWE-693 3.7 Low 2026-05-21
CVE-2026-44057 Dead bounds check in Spotlight RPC unmarshaller — Netatalk CWE-561 3.1 Low 2026-05-21
CVE-2026-7836 hextoint macro uppercase bug — Netatalk CWE-682 3.1 Low 2026-05-21
CVE-2026-7835 Format string argument mismatch — Netatalk CWE-134 3.1 Low 2026-05-21
CVE-2026-44076 Shell injection via volume path — Netatalk CWE-78 6.7 Medium 2026-05-21
CVE-2026-44073 seteuid failure ignored in auth modules — Netatalk CWE-273 4.0 Medium 2026-05-21
CVE-2026-44072 system() after failed chdir() — Netatalk CWE-78 2.5 Low 2026-05-21
CVE-2026-44070 Unbounded realloc in charset conversion — Netatalk CWE-770 3.1 Low 2026-05-21
CVE-2026-44069 Integer underflow in volxlate — Netatalk CWE-191 3.4 Low 2026-05-21
CVE-2026-44068 EA path traversal via incomplete sanitization — Netatalk CWE-22 7.6 High 2026-05-21
CVE-2026-44067 EA header parsing heap over-read — Netatalk CWE-125 3.7 Medium 2026-05-21
CVE-2026-44066 Heap out-of-bounds reads in Spotlight RPC unmarshalling — Netatalk CWE-125 7.1 High 2026-05-21
CVE-2026-44065 Off-by-two in papd lp_write() — Netatalk CWE-193 3.7 Medium 2026-05-21
CVE-2026-44064 ASP session ID out-of-bounds access — Netatalk CWE-125 7.1 High 2026-05-21
CVE-2026-44063 LDAP filter injection — Netatalk CWE-90 4.2 Medium 2026-05-21
CVE-2026-44062 Missing o_len bounds check in pull_charset_flags() — Netatalk CWE-787 7.5 High 2026-05-21
CVE-2026-44061 DES-ECB auth with timing side channel — Netatalk CWE-208 5.9 Medium 2026-05-21
CVE-2026-44060 Integer underflow in dsi_writeinit() leads to denial of service — Netatalk CWE-191 7.5 High 2026-05-21
CVE-2026-44059 Non-reentrant privilege toggle — Netatalk CWE-362 3.9 Medium 2026-05-21
CVE-2026-44058 Authentication bypass via admin auth user — Netatalk CWE-287 6.4 High 2026-05-21
CVE-2026-44056 Stack buffer overflow in desktop.c — Netatalk CWE-121 6.0 Medium 2026-05-21
CVE-2026-44055 Bitwise OR logic bug enables shell injection — Netatalk CWE-78 7.5 High 2026-05-21
CVE-2026-44054 Predictable afpd session token — Netatalk CWE-330 6.5 Medium 2026-05-21
CVE-2026-44053 Weak cryptography in DHCAST128 UAM — Netatalk CWE-327 7.4 High 2026-05-21
CVE-2026-44052 LDAP simple-bind password exposure in log output — Netatalk CWE-532 7.5 High 2026-05-21

This page lists every published CVE security advisory associated with Netatalk. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.