CVE-2026-7836
Hextoint Macro Uppercase Bug in Netatalk
Publication date: 2026-05-21
Last updated on: 2026-05-21
Assigner: securin
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| netatalk | netatalk | From 2.0.0 (inc) to 4.4.2 (inc) |
| netatalk | netatalk | 4.5.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-682 | The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a bug in the hextoint macro in Netatalk versions 2.0.0 through 4.4.2. It is related to uppercase handling in the macro. The issue was fixed in version 4.5.0.
How can this vulnerability impact me? :
The vulnerability has a CVSS v3.1 base score of 3.1, indicating a low severity impact. It requires network access with high attack complexity and low privileges, and it does not require user interaction. The impact is limited to integrity loss, with no confidentiality or availability impact.
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, upgrade Netatalk to version 4.5.0 or later, where the hextoint macro uppercase bug is fixed.