CVE-2026-44074: Netatalk

Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths.

Affected products

  • Netatalk Netatalk: from 2.1.0, up to and including 4.4.2

Published 2026-05-21. Last modified 2026-07-23.