CVE-2026-44054: Predictable afpd session token
Published May 21, 2026
·Updated
Netatalk 2.0.0 through 4.4.2 generates AFP session tokens derived from predictable process IDs, which allows a remote authenticated attacker to cause a denial of service by exploiting the reconnect mechanism.
Affected Software
1 affected component
Netatalk Netatalk>=2.0.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44054?
CVE-2026-44054 has a medium severity rating of 6.5.
2
How do I fix CVE-2026-44054?
To mitigate CVE-2026-44054, upgrade to Netatalk version 4.4.3 or later.
3
What impact does CVE-2026-44054 have on my system?
CVE-2026-44054 allows a remote authenticated attacker to cause a denial of service by exploiting predictable afpd session tokens.
4
Which versions of Netatalk are affected by CVE-2026-44054?
CVE-2026-44054 affects Netatalk versions 2.0.0 through 4.4.2.
5
What type of attack can be performed using CVE-2026-44054?
An attacker can exploit CVE-2026-44054 to perform a denial of service attack.