Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Netatalk

First CVE: Feb 9, 2005Active for: 21 yearsTotal CVEs: 50
45.7
VTI Score
High

Netatalk is an open-source implementation of the Apple File Protocol suite that enables file sharing and network services on non-Apple platforms; despite its narrow product scope, it sits in storage and network infrastructure across many legacy and heterogeneous environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by memory-safety weaknesses including out-of-bounds writes and reads, heap and stack buffer overflows, and off-by-one errors that recur across the protocol parser and service components. Defenders should prioritize inventory and patching of exposed Netatalk instances, particularly in file-sharing and legacy network infrastructure contexts; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
50
Total CVEs
More Total CVEs than 98% of tracked vendors
3.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Netatalk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 9, 2005
21 years ago
Most Recent CVE
May 21, 2026
64 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (50 CVEs).

50 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-1160CRITICAL
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac
Dec 20, 20189.884NOYES
CVE-2026-44050CRITICAL
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated
May 21, 20269.940NONO
CVE-2022-43634CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specif
Mar 29, 20239.840NONO
CVE-2026-44048HIGH
A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or caus
May 21, 20268.837NONO
CVE-2026-44047HIGH
An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data,
May 21, 20268.837NONO
CVE-2026-44051HIGH
An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-c
May 21, 20268.134NONO
CVE-2022-23121CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specif
Mar 28, 20239.834NONO
CVE-2026-44068HIGH
Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended met
May 21, 20267.633NONO
CVE-2026-44062HIGH
A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of s
May 21, 20267.533NONO
CVE-2026-44060HIGH
An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request.
May 21, 20267.533NONO
View all 50 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products50 CVEs
22%
18%
34%
26%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (10.0%)
Network40 (80.0%)
Unknown2 (4.0%)
Physical0 (0.0%)
Adjacent Network3 (6.0%)
Attack Complexity
Low27 (54.0%)
High21 (42.0%)
Unknown2 (4.0%)
User Interaction
None47 (94.0%)
Unknown2 (4.0%)
Required1 (2.0%)
Privileges Required
Low19 (38.0%)
High4 (8.0%)
None25 (50.0%)
Unknown2 (4.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (50 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Netatalk.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Netatalk — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Netatalk's Products

View all 4 CNAs →

Top CWEs