Netatalk
Vendor:
First CVE: Dec 26, 2008 · Active for 17 years
49
Total CVEs
More Total CVEs than 98% of tracked products
7.0
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Netatalk over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 26, 2008
17 years ago
Most Recent CVE
May 21, 2026
68 days ago
CVE Severity & Scoring
Netatalk49 CVEs
20%
18%
35%
27%
All CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local5 (10.2%)
Network40 (81.6%)
Unknown1 (2.0%)
Physical0 (0.0%)
Adjacent Network3 (6.1%)
Attack Complexity
Low27 (55.1%)
High21 (42.9%)
Unknown1 (2.0%)
User Interaction
None47 (95.9%)
Unknown1 (2.0%)
Required1 (2.0%)
Privileges Required
Low19 (38.8%)
High4 (8.2%)
None25 (51.0%)
Unknown1 (2.0%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1160CRITICAL Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attac | Dec 20, 2018 | 9.8 | 84 | NO | YES |
CVE-2026-44050CRITICAL A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated | May 21, 2026 | 9.9 | 40 | NO | NO |
CVE-2022-43634CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specif | Mar 29, 2023 | 9.8 | 40 | NO | NO |
CVE-2026-44048HIGH A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or caus | May 21, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-44047HIGH An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, | May 21, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-44051HIGH An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read arbitrary files or overwrite arbitrary files via attacker-c | May 21, 2026 | 8.1 | 34 | NO | NO |
CVE-2022-23121CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specif | Mar 28, 2023 | 9.8 | 34 | NO | NO |
CVE-2026-44068HIGH Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended met | May 21, 2026 | 7.6 | 33 | NO | NO |
CVE-2026-44062HIGH A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of s | May 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-44060HIGH An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to cause a denial of service via a crafted DSI write request. | May 21, 2026 | 7.5 | 33 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.0% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Netatalk
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.2.0 | 3 | 9.0 | 0.9% | 0 | 0 |
| 3.1.13 | 1 | 9.8 | 18.9% | 0 | 0 |
| 2.0.2 | 1 | 9.3 | 4.5% | 0 | 0 |
| 2.0.1 | 1 | 9.3 | 4.5% | 0 | 0 |
| 2.0.0 | 1 | 9.3 | 4.5% | 0 | 0 |
| 2.0 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.6.4a | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.6.4 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.6.3 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.6.2 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.6.1 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.6.0 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5pre8 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5pre7 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5pre6 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5pre5 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5pre4 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5pre3 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5.5 | 1 | 9.3 | 4.5% | 0 | 0 |
| 1.5.3.1 | 1 | 9.3 | 4.5% | 0 | 0 |