Technology · Netatalk
Netatalk vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 35 vulnerabilities in Netatalk: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45698, was published on 17 August 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
About Netatalk
Netatalk is a free, open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like systems to serve as file servers for macOS clients.
Latest Netatalk vulnerabilities
- CVE-2026-45698: Netatalk afpd stack buffer overflow in deletedir()highCVSS 7.5EPSS 0.4%
- CVE-2026-45699: Netatalk afpd stack buffer overflow in copydir()highCVSS 7.5EPSS 0.4%
- CVE-2026-7837: Netatalk TOCTOU race condition in ad_flushlowCVSS 3.7
- CVE-2026-44075: Netatalk missing break statement in DSI OpenSessionlowCVSS 3.7
- CVE-2026-44074: Netatalk incorrect calculation in ACL error handlinglowCVSS 3.7
- CVE-2026-44071: Netatalk disabled FORTIFY_SOURCE in MySQL CNID backendlowCVSS 3.7
- CVE-2026-44057: Netatalk dead bounds check in Spotlight RPC unmarshallerlowCVSS 3.1
- CVE-2026-7836: Netatalk incorrect calculation in hextoint macrolowCVSS 3.1
- CVE-2026-7835: Netatalk format string argument mismatch in logging componentlowCVSS 3.1
- CVE-2026-44076: Netatalk shell injection in Spotlight volume pathmediumCVSS 6.7
- CVE-2026-44073: Netatalk improper privilege dropping in authentication modulesmediumCVSS 5
- CVE-2026-44072: Netatalk improper directory handling during CNID cleanuplowCVSS 3
- CVE-2026-44070: Netatalk unbounded realloc in charset conversionlowCVSS 3.1
- CVE-2026-44069: Netatalk integer underflow in volxlatelowCVSS 3.9
- CVE-2026-44068: Netatalk path traversal in extended attribute handlinghighCVSS 7.6
- CVE-2026-44067: Netatalk heap over-read in extended attribute header parsingmediumCVSS 4.2
- CVE-2026-44066: Netatalk heap out-of-bounds read in Spotlight RPC unmarshallinghighCVSS 7.1
- CVE-2026-44065: Netatalk off-by-two in papd lp_writemediumCVSS 4.2
- CVE-2026-44064: Netatalk out-of-bounds access in ASP session ID handlinghighCVSS 7.1
- CVE-2026-44063: Netatalk LDAP filter injection in LDAP-backed operationsmediumCVSS 4.2
- CVE-2026-44062: Netatalk out-of-bounds write in pull_charset_flagshighCVSS 7.5
- CVE-2026-44061: Netatalk timing side channel in Randnum authentication mechanismmediumCVSS 5.9
- CVE-2026-44060: Netatalk integer underflow in dsi_writeinithighCVSS 7.5
- CVE-2026-44059: Netatalk non-reentrant privilege toggle race conditionmediumCVSS 4.5
- CVE-2026-44058: Netatalk authentication bypass in admin auth user fallbackhighCVSS 7.2
Most severe Netatalk vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-44050: Netatalk heap buffer overflow in CNID daemon comm_rcvcriticalCVSS 9.9
- CVE-2026-44048: Netatalk stack buffer overflow in convert_charsethighCVSS 8.8
- CVE-2026-44047: Netatalk SQL injection in MySQL CNID backendhighCVSS 8.8
- CVE-2026-44051: Netatalk arbitrary file read via symlink creation in afpdhighCVSS 8.1
- CVE-2026-44068: Netatalk path traversal in extended attribute handlinghighCVSS 7.6
- CVE-2026-45698: Netatalk afpd stack buffer overflow in deletedir()highCVSS 7.5EPSS 0.4%
- CVE-2026-45699: Netatalk afpd stack buffer overflow in copydir()highCVSS 7.5EPSS 0.4%
- CVE-2026-44062: Netatalk out-of-bounds write in pull_charset_flagshighCVSS 7.5
- CVE-2026-44060: Netatalk integer underflow in dsi_writeinithighCVSS 7.5
- CVE-2026-44055: Netatalk shell injection in file change event notification scriptshighCVSS 7.5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/netatalk.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Netatalk vulnerabilities", https://junglewise.ai/threats/technologies/netatalk, 26 September 2026.