CVE-2026-48487Disclosure(paulsm / zeroconf)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it against self._data_len, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to send a TXT, HINFO, or A/AAAA record with rdlength=65535 and seed DNSCache and ServiceInfo.properties with truncated, attacker-shaped key/value or address records. This issue is fixed in version 0.149.16.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-130

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • zeroconf

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-07-17)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
zeroconf

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-22: 1Mentions · 2026-07-17: 2Technical Details · 2026-06-22: 1Technical Details · 2026-07-17: 206-2207-17
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-221
Disclosure1
2026-07-172
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-48487 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/inco… https://www.cve.org/CVERecord?id=CVE-2026-48487 ----- Traducción: CVE-2026-48487 Zer… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑48487, highlighting a flaw in Zeroconf’s multicast DNS service discovery in versions before 0.149.16, but it does not provide any proof‑of‑concept, exploit code, or remediation details.

    0000042
    92 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48487 Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/inco… https://www.cve.org/CVERecord?id=CVE-2026-48487

    Post summary

    The post documents a CVE in Zeroconf, naming the vulnerable functions and version range, but it provides no exploit, PoC, or patch details.

    00000672
    57.8K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 zeroconf (#python-zeroconf), Cache Corruption via Unvalidated RDLENGTH, #CVE-2026-48487 (Low) -DC-Jun2026-567 https://dailycve.com/zeroconf-python-zeroconf-cache-corruption-via-unvalidated-rdlength-cve-2026-48487-low-dc-jun2026-567/

    Post summary

    The post announces CVE‑2026‑48487, a low‑severity cache corruption issue in python‑zeroconf caused by an unvalidated RDLENGTH field. No PoC, exploit, or mitigation is provided.

    0000046
    216 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppaulsmzeroconf-python-

Explore more