CVE-2026-44061: DES-ECB auth with timing side channel
Published May 21, 2026
·Updated
Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover authentication credentials via timing analysis.
Affected Software
1 affected component
Netatalk Netatalk>=1.5.0<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44061?
The severity of CVE-2026-44061 is rated as medium with a score of 5.9.
2
How do I fix CVE-2026-44061?
To fix CVE-2026-44061, upgrade to Netatalk version 4.5.0 or later.
3
What is the main risk associated with CVE-2026-44061?
The main risk associated with CVE-2026-44061 is remote attackers potentially recovering authentication credentials through timing analysis.
4
Which versions of Netatalk are affected by CVE-2026-44061?
Netatalk versions from 1.5.0 through 4.4.2 are affected by CVE-2026-44061.
5
What type of attack does CVE-2026-44061 involve?
CVE-2026-44061 involves a timing side channel attack related to DES-ECB authentication.