Netatalk is an open-source implementation of the Apple File Protocol suite that enables file sharing and network services on non-Apple platforms; despite its narrow product scope, it sits in storage and network infrastructure across many legacy and heterogeneous environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by memory-safety weaknesses including out-of-bounds writes and reads, heap and stack buffer overflows, and off-by-one errors that recur across the protocol parser and service components. Defenders should prioritize inventory and patching of exposed Netatalk instances, particularly in file-sharing and legacy network infrastructure contexts; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netatalk over time
Signals from CVEs in this vendor scope (50 CVEs).
50 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1160CRITICAL Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac | Dec 20, 2018 | 9.8 | 84 | NO | YES |
CVE-2026-44050CRITICAL A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated | May 21, 2026 | 9.9 | 40 | NO | NO |
CVE-2022-43634CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specif | Mar 29, 2023 | 9.8 | 40 | NO | NO |
CVE-2026-44048HIGH A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or caus | May 21, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-44047HIGH An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, | May 21, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-44051HIGH An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-c | May 21, 2026 | 8.1 | 34 | NO | NO |
CVE-2022-23121CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specif | Mar 28, 2023 | 9.8 | 34 | NO | NO |
CVE-2026-44068HIGH Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended met | May 21, 2026 | 7.6 | 33 | NO | NO |
CVE-2026-44062HIGH A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of s | May 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-44060HIGH An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request. | May 21, 2026 | 7.5 | 33 | NO | NO |
Signals from CVEs in this vendor scope (50 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netatalk.
Media articles that mention a CVE ID that affects a product developed by Netatalk — matched by CVE ID, not by vendor name.