Medium severityNVD Advisory· Published Jul 17, 2026· Updated Jul 23, 2026
CVE-2026-48487
CVE-2026-48487
Description
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it against self._data_len, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to send a TXT, HINFO, or A/AAAA record with rdlength=65535 and seed DNSCache and ServiceInfo.properties with truncated, attacker-shaped key/value or address records. This issue is fixed in version 0.149.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
zeroconfPyPI | < 0.149.16 | 0.149.16 |
Affected products
3- Range: <0.149.16
- osv-coords2 versionspkg:rpm/opensuse/python-zeroconf&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/python-zeroconf&distro=openSUSE%20Tumbleweed
< 0.136.0-bp160.2.1+ 1 more
- (no CPE)range: < 0.136.0-bp160.2.1
- (no CPE)range: < 0.149.16-1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-qc2x-6f54-m6h9ghsaADVISORY
- github.com/python-zeroconf/python-zeroconf/issues/1752nvdWEB
- github.com/python-zeroconf/python-zeroconf/pull/1756nvdWEB
- github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-qc2x-6f54-m6h9nvdWEB
- github.com/python-zeroconf/python-zeroconf/commit/544449596e645fcaad3834fa0cb614a54f847a82nvd
- github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.16nvd
News mentions
0No linked articles in our index yet.