Memory Reallocation Vulnerability in Netatalk Affected by Charset Conversion Issues
CVE-2026-44070

3.1LOW

Key Information:

Vendor

Netatalk

Status
Vendor
CVE Published:
21 May 2026

What is CVE-2026-44070?

A significant vulnerability exists in the charset conversion code of Netatalk, ranging from versions 2.0.0 to 4.4.2, which allows remote authenticated attackers to exploit unbounded memory reallocation. By crafting specific character conversion requests, an attacker can provoke minor denial of service conditions, potentially disrupting service functionality. It is crucial for users of these versions to review their security practices and apply the necessary mitigations to protect their systems.

Affected Version(s)

Netatalk 2.0.0 <= 4.4.2

Netatalk 4.5.0

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Arjun Basnet from Securin
.