zeroconf vulnerabilities
CVEs whose affected-version data names the zeroconf package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
5 CVEsRSS
CVE-2026-48487Medium· 6.5zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet
zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet
CVE-2026-48045Medium· 6.5python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
CVE-2026-47184Medium· 6.5zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
CVE-2026-47183Medium· 6.5zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
CVE-2026-47180Medium· 6.5zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service