Home
HIGH: 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:NDefault status
unaffected
1.5.0 (semver)
affected
4.5.0 (semver)
unaffected
Description
Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker to obtain authentication credentials or impersonate a user via cryptanalytic attack.
Problem types
Use of a Broken or Risky Cryptographic Algorithm
Product status
1.5.0 (semver)
4.5.0 (semver)
Credits
Arjun Basnet from Securin
References
netatalk.io/security/CVE-2026-44053 (Netatalk Security Advisory CVE-2026-44053)