Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Avahi

First CVE: May 10, 2006Active for: 20 yearsTotal CVEs: 25
26.9
VTI Score
Low

Avahi is a network service discovery daemon widely embedded in Linux distributions and networked appliances for zero-configuration mDNS/DNS-SD functionality, presenting a modest but strategically important attack surface in the landscape. Its vulnerability profile concentrates on a single product—the Avahi daemon itself—and clusters around assertion failures, resource-consumption flaws, infinite loops, and link-following issues that reflect the parsing and service-enumeration demands of multicast DNS handling. These weakness classes tend to manifest as denial-of-service and stability conditions rather than high-severity exploits, and they recur across the protocol-handling and file-access layers of the codebase. Defenders should monitor this vendor's releases for infrastructure that relies on mDNS discovery (embedded Linux devices, enterprise networks with mdns traffic, and containerized environments) and treat patches as a steady maintenance priority rather than emergency updates. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 16% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Avahi over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 10, 2006
20 years ago
Most Recent CVE
Apr 3, 2026
112 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-5081MEDIUM
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) v
Dec 17, 20085.062NOYES
CVE-2011-1002MEDIUM
avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to
Feb 22, 20115.033NONO
CVE-2017-6519CRITICAL
avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a den
May 1, 20179.130NONO
CVE-2021-26720HIGH
avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of serv
Feb 17, 20217.824NONO
CVE-2025-68468MEDIUM
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolici
Jan 12, 20266.523NONO
CVE-2026-24401MEDIUM
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segment
Jan 24, 20266.522NONO
CVE-2025-68471MEDIUM
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsoli
Jan 12, 20266.522NONO
CVE-2025-59529MEDIUM
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ign
Dec 18, 20255.522NONO
CVE-2026-34933MEDIUM
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-d
Apr 3, 20265.521NONO
CVE-2025-68276MEDIUM
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-dae
Jan 12, 20265.521NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
16%
72%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (48.0%)
Network4 (16.0%)
Unknown9 (36.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (64.0%)
High0 (0.0%)
Unknown9 (36.0%)
User Interaction
None13 (52.0%)
Unknown9 (36.0%)
Required3 (12.0%)
Privileges Required
Low12 (48.0%)
High0 (0.0%)
None4 (16.0%)
Unknown9 (36.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.0% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Avahi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Avahi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Avahi's Products

View all 4 CNAs →

Top CWEs