CVE-2026-44064: ASP session ID out-of-bounds access
Published May 21, 2026
·Updated
An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to obtain limited information or cause a denial of service via a crafted ASP request.
Affected Software
1 affected component
Netatalk Netatalk>=1.3<=4.4.2
Event History
May 21, 2026
CVE Published
via MITRE·07:34 AM
Data Sourced
via MITRE·07:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-44064?
The severity of CVE-2026-44064 is rated as high with a score of 7.1.
2
How do I fix CVE-2026-44064?
To fix CVE-2026-44064, update Netatalk to version 4.4.3 or later.
3
What type of attack does CVE-2026-44064 allow?
CVE-2026-44064 allows an adjacent network attacker to perform an out-of-bounds read and potentially cause a denial of service.
4
Which versions of Netatalk are affected by CVE-2026-44064?
CVE-2026-44064 affects Netatalk versions 1.3 through 4.4.2.
5
Is user interaction required to exploit CVE-2026-44064?
No, user interaction is not required to exploit CVE-2026-44064.