CVE-2026-44053: Weak cryptography in DHCAST128 UAM
Published May 21, 2026
·Updated
Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic attack.
Affected Software
1 affected component
Netatalk Netatalk>=1.5.0<=4.2.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44053?
CVE-2026-44053 has a severity rating of 7.4, indicating a high risk level.
2
What vulnerability does CVE-2026-44053 address?
CVE-2026-44053 addresses weak cryptography in DHCAST128 UAM used in Netatalk versions 1.5.0 through 4.2.2.
3
How do I fix CVE-2026-44053?
To fix CVE-2026-44053, upgrade Netatalk to version 4.5.0 or later, where the vulnerability is resolved.
4
What impact does CVE-2026-44053 have on security?
CVE-2026-44053 allows remote attackers to obtain authentication credentials or impersonate a user via cryptanalytic attacks.
5
Which versions of Netatalk are affected by CVE-2026-44053?
Netatalk versions 1.5.0 through 4.2.2 are affected by CVE-2026-44053.