CVE-2026-44075CWE-484

Missing break in DSI OpenSession

Low · published May 21, 2026

CVSS v3.1
3.7
EPSS
0%
Percentile
25.7
In the wild
Unconfirmed
What it is

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI session options.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00329 · 25.7th percentile
Weakness
CWE-484 · Omitted Break Statement in Switch
Published
2026-05-21T08:14Z
EPSS history
Timeline
  • 21 MAY 08:14Z
    Missing break in DSI OpenSession
    cvelistv5