CVE-2026-44068
EUVD-2026-3121521.05.2026, 08:16
Incomplete sanitization of extended attribute (EA) path components in Netatalk 2.1.0 through 4.4.2 allows a remote authenticated attacker to write to files outside the intended metadata namespace via crafted EA names.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| netatalk | netatalk | 2.1.0 ≤ 𝑥 ≤ 4.4.2 | CNA |
Debian Releases