Avahi is a network service discovery daemon widely embedded in Linux distributions and networked appliances for zero-configuration mDNS/DNS-SD functionality, presenting a modest but strategically important attack surface in the landscape. Its vulnerability profile concentrates on a single product—the Avahi daemon itself—and clusters around assertion failures, resource-consumption flaws, infinite loops, and link-following issues that reflect the parsing and service-enumeration demands of multicast DNS handling. These weakness classes tend to manifest as denial-of-service and stability conditions rather than high-severity exploits, and they recur across the protocol-handling and file-access layers of the codebase. Defenders should monitor this vendor's releases for infrastructure that relies on mDNS discovery (embedded Linux devices, enterprise networks with mdns traffic, and containerized environments) and treat patches as a steady maintenance priority rather than emergency updates. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Avahi over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5081MEDIUM The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 allows remote attackers to cause a denial of service (crash) v | Dec 17, 2008 | 5.0 | 62 | NO | YES |
CVE-2011-1002MEDIUM avahi-core/socket.c in avahi-daemon in Avahi before 0.6.29 allows remote attackers to cause a denial of service (infinite loop) via an empty mDNS (1) IPv4 or (2) IPv6 UDP packet to | Feb 22, 2011 | 5.0 | 33 | NO | NO |
CVE-2017-6519CRITICAL avahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows remote attackers to cause a den | May 1, 2017 | 9.1 | 30 | NO | NO |
CVE-2021-26720HIGH avahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local attacker to cause a denial of serv | Feb 17, 2021 | 7.8 | 24 | NO | NO |
CVE-2025-68468MEDIUM Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolici | Jan 12, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-24401MEDIUM Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daemon can be crashed via a segment | Jan 24, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-68471MEDIUM Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsoli | Jan 12, 2026 | 6.5 | 22 | NO | NO |
CVE-2025-59529MEDIUM Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2, the simple protocol server ign | Dec 18, 2025 | 5.5 | 22 | NO | NO |
CVE-2026-34933MEDIUM Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-d | Apr 3, 2026 | 5.5 | 21 | NO | NO |
CVE-2025-68276MEDIUM Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged local users can crash avahi-dae | Jan 12, 2026 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Avahi.
Media articles that mention a CVE ID that affects a product developed by Avahi — matched by CVE ID, not by vendor name.