VYPR

rpm package

opensuse/python-zeroconf&distro=openSUSE Leap 16.0

pkg:rpm/opensuse/python-zeroconf&distro=openSUSE%20Leap%2016.0

Vulnerabilities (5)

  • CVE-2026-48487MedJul 17, 2026
    affected < 0.136.0-bp160.2.1fixed 0.136.0-bp160.2.1

    Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it against self._data_len, allowing un

  • CVE-2026-48045MedJul 17, 2026
    affected < 0.136.0-bp160.2.1fixed 0.136.0-bp160.2.1

    Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming query, each up to _MAX_MSG_ABSOLUTE = 8966 bytes, in self._deferred[addr] and armed a per-address timer in

  • CVE-2026-47184MedJul 17, 2026
    affected < 0.136.0-bp160.2.1fixed 0.136.0-bp160.2.1

    Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache without a cap, allowing unauthenticated hosts on the local link over UDP/535

  • CVE-2026-47183MedJul 17, 2026
    affected < 0.136.0-bp160.2.1fixed 0.136.0-bp160.2.1

    Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup methods stored an unbounded _seen_logs dictionary keyed by attacker-influenced IncomingDecodeError messages, re

  • CVE-2026-47180MedJul 17, 2026
    affected < 0.136.0-bp160.2.1fixed 0.136.0-bp160.2.1

    Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS packet carrying chained pointers can trigger a RecursionError that escapes DNSInco