Junglewise Threat Intelligence

CVE-2026-44053: Netatalk weak cryptography in DHCAST128 UAM

CVE-2026-44053 · Severity: high · CVSS 7.4 · Published 2026-05-21

Technologies: Netatalk team Netatalk.

Executive brief

Netatalk, an open-source implementation of the Apple Filing Protocol (AFP) used for file sharing, contains a security weakness in one of its older authentication methods. This flaw involves the use of outdated encryption that could allow a sophisticated attacker on the same network to potentially intercept or manipulate login credentials. While the risk is considered low for most modern setups, organizations using legacy authentication should upgrade to prevent unauthorized access to shared files.

Technical details

Netatalk versions 1.5.0 through 4.2.2 are vulnerable to a cryptographic weakness (CWE-327) within the DHCAST128 User Authentication Module (UAM). The implementation utilizes a 128-bit Diffie-Hellman prime, which is computationally insufficient by modern standards to protect against decryption or person-in-the-middle attacks. An unauthenticated attacker with a suitable network position could potentially exploit this weak negotiation to compromise session confidentiality and integrity. The vulnerability is mitigated by the high complexity required for exploitation and the requirement for legacy negotiation conditions. Users are advised to upgrade to Netatalk 4.5.0 or disable the 'uams_dhx.so' module in favor of 'uams_dhx2.so'.

Affected products

  • Netatalk team Netatalk 1.5.0 through 4.2.2

Timeline

  • 2026-05-13: disclosed: Initial disclosure date
  • 2026-05-21: advisory: NVD and vendor advisory published
  • 2026-05-21: patched: Fixed in version 4.5.0

References