CVE-2026-44061 Details
Description
Netatalk 1.5.0 through 4.4.2 uses DES-ECB for authentication with a timing side channel, which allows a remote attacker to recover authentication credentials via timing analysis.
A timing side channel vulnerability in the DES-ECB authentication mechanism has been identified in Netatalk versions 1.5.0 through 4.4.2. This vulnerability arises because the authentication process uses outdated cryptography and performs comparisons in a non-constant-time manner, potentially allowing for password-equivalent exposure or offline attacks.
Users can upgrade to Netatalk version 4.5.0 or later, which includes the necessary patch. Alternatively, version 4.4.2 can be patched manually. The Netatalk team advises against applying the patch to existing deployments due to the low risk of practical exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 21, 2026CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://netatalk.io/security/CVE-2026-44061 | securin | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-208 | Observable Timing Discrepancy | securin |
Affected Products
| Product | Versions |
|---|---|
| Netatalk | >= 1.5.0, <= 4.4.2 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | securin |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 21, 2026 | CVE Modified | securin |
| May 21, 2026 | New CVE Received | securin |
Volerion