Dead Bounds Check Vulnerability in Netatalk from Inventiv
CVE-2026-44057

3.1LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44057?

A dead bounds check in the Spotlight RPC unmarshaller within Netatalk versions 3.0.0 through 4.4.2 creates an ineffective bounds protection scenario. This weakness allows a remote authenticated attacker to exploit crafted Spotlight RPC requests, potentially gaining limited access to sensitive information. Users of the affected versions should implement mitigations to reduce exposure.

Affected Version(s)

Netatalk 3.0.0 <= 4.4.2

Netatalk 4.4.3

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.