{"schema_version":1,"title":"Netatalk vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 35 vulnerabilities in Netatalk: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-45698, was published on 17 August 2026.","url":"https://junglewise.ai/threats/technologies/netatalk","json_url":"https://junglewise.ai/threats/technologies/netatalk.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/netatalk","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":15,"all_time":35,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":35},"latest":[{"cve":"CVE-2026-45698","cvss":7.5,"epss":0.0045,"slug":"cve-2026-45698-netatalk-afpd-stack-buffer-overflow-in-deletedir","title":"Netatalk afpd stack buffer overflow in deletedir()","severity":"high","exploited":false,"published_at":"2026-08-17T19:16:30.703+00:00","url":"https://junglewise.ai/threats/cve-2026-45698-netatalk-afpd-stack-buffer-overflow-in-deletedir"},{"cve":"CVE-2026-45699","cvss":7.5,"epss":0.0045,"slug":"cve-2026-45699-netatalk-afpd-stack-buffer-overflow-in-copydir","title":"Netatalk afpd stack buffer overflow in copydir()","severity":"high","exploited":false,"published_at":"2026-08-14T19:17:18.267+00:00","url":"https://junglewise.ai/threats/cve-2026-45699-netatalk-afpd-stack-buffer-overflow-in-copydir"},{"cve":"CVE-2026-7837","cvss":3.7,"slug":"cve-2026-7837-netatalk-toctou-race-condition-in-ad-flush","title":"Netatalk TOCTOU race condition in ad_flush","severity":"low","exploited":false,"published_at":"2026-05-21T09:16:30.803+00:00","url":"https://junglewise.ai/threats/cve-2026-7837-netatalk-toctou-race-condition-in-ad-flush"},{"cve":"CVE-2026-44075","cvss":3.7,"slug":"cve-2026-44075-netatalk-missing-break-statement-in-dsi-opensession","title":"Netatalk missing break statement in DSI OpenSession","severity":"low","exploited":false,"published_at":"2026-05-21T09:16:29.77+00:00","url":"https://junglewise.ai/threats/cve-2026-44075-netatalk-missing-break-statement-in-dsi-opensession"},{"cve":"CVE-2026-44074","cvss":3.7,"slug":"cve-2026-44074-netatalk-incorrect-calculation-in-acl-error-handling","title":"Netatalk incorrect calculation in ACL error handling","severity":"low","exploited":false,"published_at":"2026-05-21T09:16:29.65+00:00","url":"https://junglewise.ai/threats/cve-2026-44074-netatalk-incorrect-calculation-in-acl-error-handling"},{"cve":"CVE-2026-44071","cvss":3.7,"slug":"cve-2026-44071-netatalk-disabled-fortify-source-in-mysql-cnid-backend","title":"Netatalk disabled FORTIFY_SOURCE in MySQL CNID backend","severity":"low","exploited":false,"published_at":"2026-05-21T09:16:29.34+00:00","url":"https://junglewise.ai/threats/cve-2026-44071-netatalk-disabled-fortify-source-in-mysql-cnid-backend"},{"cve":"CVE-2026-44057","cvss":3.1,"slug":"cve-2026-44057-netatalk-dead-bounds-check-in-spotlight-rpc-unmarshaller","title":"Netatalk dead bounds check in Spotlight RPC unmarshaller","severity":"low","exploited":false,"published_at":"2026-05-21T09:16:27.93+00:00","url":"https://junglewise.ai/threats/cve-2026-44057-netatalk-dead-bounds-check-in-spotlight-rpc-unmarshaller"},{"cve":"CVE-2026-7836","cvss":3.1,"slug":"cve-2026-7836-netatalk-incorrect-calculation-in-hextoint-macro","title":"Netatalk incorrect calculation in hextoint macro","severity":"low","exploited":false,"published_at":"2026-05-21T08:16:23.403+00:00","url":"https://junglewise.ai/threats/cve-2026-7836-netatalk-incorrect-calculation-in-hextoint-macro"},{"cve":"CVE-2026-7835","cvss":3.1,"slug":"cve-2026-7835-netatalk-format-string-argument-mismatch-in-logging-component","title":"Netatalk format string argument mismatch in logging component","severity":"low","exploited":false,"published_at":"2026-05-21T08:16:23.277+00:00","url":"https://junglewise.ai/threats/cve-2026-7835-netatalk-format-string-argument-mismatch-in-logging-component"},{"cve":"CVE-2026-44076","cvss":6.7,"slug":"cve-2026-44076-netatalk-shell-injection-in-spotlight-volume-path","title":"Netatalk shell injection in Spotlight volume path","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:23.023+00:00","url":"https://junglewise.ai/threats/cve-2026-44076-netatalk-shell-injection-in-spotlight-volume-path"},{"cve":"CVE-2026-44073","cvss":5,"slug":"cve-2026-44073-netatalk-improper-privilege-dropping-in-authentication-modules","title":"Netatalk improper privilege dropping in authentication modules","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:22.913+00:00","url":"https://junglewise.ai/threats/cve-2026-44073-netatalk-improper-privilege-dropping-in-authentication-modules"},{"cve":"CVE-2026-44072","cvss":3,"slug":"cve-2026-44072-netatalk-improper-directory-handling-during-cnid-cleanup","title":"Netatalk improper directory handling during CNID cleanup","severity":"low","exploited":false,"published_at":"2026-05-21T08:16:22.807+00:00","url":"https://junglewise.ai/threats/cve-2026-44072-netatalk-improper-directory-handling-during-cnid-cleanup"},{"cve":"CVE-2026-44070","cvss":3.1,"slug":"cve-2026-44070-netatalk-unbounded-realloc-in-charset-conversion","title":"Netatalk unbounded realloc in charset conversion","severity":"low","exploited":false,"published_at":"2026-05-21T08:16:22.693+00:00","url":"https://junglewise.ai/threats/cve-2026-44070-netatalk-unbounded-realloc-in-charset-conversion"},{"cve":"CVE-2026-44069","cvss":3.9,"slug":"cve-2026-44069-netatalk-integer-underflow-in-volxlate","title":"Netatalk integer underflow in volxlate","severity":"low","exploited":false,"published_at":"2026-05-21T08:16:22.583+00:00","url":"https://junglewise.ai/threats/cve-2026-44069-netatalk-integer-underflow-in-volxlate"},{"cve":"CVE-2026-44068","cvss":7.6,"slug":"cve-2026-44068-netatalk-path-traversal-in-extended-attribute-handling","title":"Netatalk path traversal in extended attribute handling","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:22.473+00:00","url":"https://junglewise.ai/threats/cve-2026-44068-netatalk-path-traversal-in-extended-attribute-handling"},{"cve":"CVE-2026-44067","cvss":4.2,"slug":"cve-2026-44067-netatalk-heap-over-read-in-extended-attribute-header-parsing","title":"Netatalk heap over-read in extended attribute header parsing","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:22.363+00:00","url":"https://junglewise.ai/threats/cve-2026-44067-netatalk-heap-over-read-in-extended-attribute-header-parsing"},{"cve":"CVE-2026-44066","cvss":7.1,"slug":"cve-2026-44066-netatalk-heap-out-of-bounds-read-in-spotlight-rpc-unmarshalling","title":"Netatalk heap out-of-bounds read in Spotlight RPC unmarshalling","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:22.253+00:00","url":"https://junglewise.ai/threats/cve-2026-44066-netatalk-heap-out-of-bounds-read-in-spotlight-rpc-unmarshalling"},{"cve":"CVE-2026-44065","cvss":4.2,"slug":"cve-2026-44065-netatalk-off-by-two-in-papd-lp-write","title":"Netatalk off-by-two in papd lp_write","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:22.143+00:00","url":"https://junglewise.ai/threats/cve-2026-44065-netatalk-off-by-two-in-papd-lp-write"},{"cve":"CVE-2026-44064","cvss":7.1,"slug":"cve-2026-44064-netatalk-out-of-bounds-access-in-asp-session-id-handling","title":"Netatalk out-of-bounds access in ASP session ID handling","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:22.02+00:00","url":"https://junglewise.ai/threats/cve-2026-44064-netatalk-out-of-bounds-access-in-asp-session-id-handling"},{"cve":"CVE-2026-44063","cvss":4.2,"slug":"cve-2026-44063-netatalk-ldap-filter-injection-in-ldap-backed-operations","title":"Netatalk LDAP filter injection in LDAP-backed operations","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:21.907+00:00","url":"https://junglewise.ai/threats/cve-2026-44063-netatalk-ldap-filter-injection-in-ldap-backed-operations"},{"cve":"CVE-2026-44062","cvss":7.5,"slug":"cve-2026-44062-netatalk-out-of-bounds-write-in-pull-charset-flags","title":"Netatalk out-of-bounds write in pull_charset_flags","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-44062-netatalk-out-of-bounds-write-in-pull-charset-flags"},{"cve":"CVE-2026-44061","cvss":5.9,"slug":"cve-2026-44061-netatalk-timing-side-channel-in-randnum-authentication-mechanism","title":"Netatalk timing side channel in Randnum authentication mechanism","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:21.687+00:00","url":"https://junglewise.ai/threats/cve-2026-44061-netatalk-timing-side-channel-in-randnum-authentication-mechanism"},{"cve":"CVE-2026-44060","cvss":7.5,"slug":"cve-2026-44060-netatalk-integer-underflow-in-dsi-writeinit","title":"Netatalk integer underflow in dsi_writeinit","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:21.577+00:00","url":"https://junglewise.ai/threats/cve-2026-44060-netatalk-integer-underflow-in-dsi-writeinit"},{"cve":"CVE-2026-44059","cvss":4.5,"slug":"cve-2026-44059-netatalk-non-reentrant-privilege-toggle-race-condition","title":"Netatalk non-reentrant privilege toggle race condition","severity":"medium","exploited":false,"published_at":"2026-05-21T08:16:21.467+00:00","url":"https://junglewise.ai/threats/cve-2026-44059-netatalk-non-reentrant-privilege-toggle-race-condition"},{"cve":"CVE-2026-44058","cvss":7.2,"slug":"cve-2026-44058-netatalk-authentication-bypass-in-admin-auth-user-fallback","title":"Netatalk authentication bypass in admin auth user fallback","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:21.353+00:00","url":"https://junglewise.ai/threats/cve-2026-44058-netatalk-authentication-bypass-in-admin-auth-user-fallback"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Netatalk","slug":"netatalk","vendor":{"name":"Netatalk","slug":"netatalk","url":"https://junglewise.ai/threats/vendors/netatalk"},"aliases":[],"category":"library","homepage":"https://netatalk.io/","repo_url":"https://github.com/Netatalk/netatalk","description":"Netatalk is a free, open-source implementation of the Apple Filing Protocol (AFP), allowing Unix-like systems to serve as file servers for macOS clients.","url":"https://junglewise.ai/threats/technologies/netatalk"},"most_severe":[{"cve":"CVE-2026-44050","cvss":9.9,"slug":"cve-2026-44050-netatalk-heap-buffer-overflow-in-cnid-daemon-comm-rcv","title":"Netatalk heap buffer overflow in CNID daemon comm_rcv","severity":"critical","exploited":false,"published_at":"2026-05-21T08:16:20.58+00:00","url":"https://junglewise.ai/threats/cve-2026-44050-netatalk-heap-buffer-overflow-in-cnid-daemon-comm-rcv"},{"cve":"CVE-2026-44048","cvss":8.8,"slug":"cve-2026-44048-netatalk-stack-buffer-overflow-in-convert-charset","title":"Netatalk stack buffer overflow in convert_charset","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:20.36+00:00","url":"https://junglewise.ai/threats/cve-2026-44048-netatalk-stack-buffer-overflow-in-convert-charset"},{"cve":"CVE-2026-44047","cvss":8.8,"slug":"cve-2026-44047-netatalk-sql-injection-in-mysql-cnid-backend","title":"Netatalk SQL injection in MySQL CNID backend","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:20.173+00:00","url":"https://junglewise.ai/threats/cve-2026-44047-netatalk-sql-injection-in-mysql-cnid-backend"},{"cve":"CVE-2026-44051","cvss":8.1,"slug":"cve-2026-44051-netatalk-arbitrary-file-read-via-symlink-creation-in-afpd","title":"Netatalk arbitrary file read via symlink creation in afpd","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:20.69+00:00","url":"https://junglewise.ai/threats/cve-2026-44051-netatalk-arbitrary-file-read-via-symlink-creation-in-afpd"},{"cve":"CVE-2026-44068","cvss":7.6,"slug":"cve-2026-44068-netatalk-path-traversal-in-extended-attribute-handling","title":"Netatalk path traversal in extended attribute handling","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:22.473+00:00","url":"https://junglewise.ai/threats/cve-2026-44068-netatalk-path-traversal-in-extended-attribute-handling"},{"cve":"CVE-2026-45698","cvss":7.5,"epss":0.0045,"slug":"cve-2026-45698-netatalk-afpd-stack-buffer-overflow-in-deletedir","title":"Netatalk afpd stack buffer overflow in deletedir()","severity":"high","exploited":false,"published_at":"2026-08-17T19:16:30.703+00:00","url":"https://junglewise.ai/threats/cve-2026-45698-netatalk-afpd-stack-buffer-overflow-in-deletedir"},{"cve":"CVE-2026-45699","cvss":7.5,"epss":0.0045,"slug":"cve-2026-45699-netatalk-afpd-stack-buffer-overflow-in-copydir","title":"Netatalk afpd stack buffer overflow in copydir()","severity":"high","exploited":false,"published_at":"2026-08-14T19:17:18.267+00:00","url":"https://junglewise.ai/threats/cve-2026-45699-netatalk-afpd-stack-buffer-overflow-in-copydir"},{"cve":"CVE-2026-44062","cvss":7.5,"slug":"cve-2026-44062-netatalk-out-of-bounds-write-in-pull-charset-flags","title":"Netatalk out-of-bounds write in pull_charset_flags","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:21.797+00:00","url":"https://junglewise.ai/threats/cve-2026-44062-netatalk-out-of-bounds-write-in-pull-charset-flags"},{"cve":"CVE-2026-44060","cvss":7.5,"slug":"cve-2026-44060-netatalk-integer-underflow-in-dsi-writeinit","title":"Netatalk integer underflow in dsi_writeinit","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:21.577+00:00","url":"https://junglewise.ai/threats/cve-2026-44060-netatalk-integer-underflow-in-dsi-writeinit"},{"cve":"CVE-2026-44055","cvss":7.5,"slug":"cve-2026-44055-netatalk-shell-injection-in-file-change-event-notification","title":"Netatalk shell injection in file change event notification scripts","severity":"high","exploited":false,"published_at":"2026-05-21T08:16:21.137+00:00","url":"https://junglewise.ai/threats/cve-2026-44055-netatalk-shell-injection-in-file-change-event-notification"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}