CVE-2026-44062
Netatalk
A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of service via crafted character set data.
- CVSS
- 7.5
- EPSS
- 0.36% 28.4% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.21