VulnSea

zeroconf vulnerabilities

CVEs whose affected-version data names the zeroconf package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-48487Medium· 6.5
3mo ago

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet

Sunlitzeroconf · zeroconfEPSS 0.25%via GHSA
CVE-2026-48045Medium· 6.5
3mo ago

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood

Sunlitzeroconf · zeroconfEPSS 0.37%via GHSA
CVE-2026-47184Medium· 6.5
3mo ago

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood

Sunlitzeroconf · zeroconfEPSS 0.39%via OSV
CVE-2026-47183Medium· 6.5
3mo ago

zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion

zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion

Sunlitzeroconf · zeroconfEPSS 0.39%via OSV
CVE-2026-47180Medium· 6.5
3mo ago

zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service

zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service

Sunlitzeroconf · zeroconfEPSS 0.37%via OSV
zeroconf vulnerabilities (CVEs) · VulnSea