CVE-2026-48487
MEDIUMpython-zeroconf < 0.149.16 - LAN-Local mDNS RDLENGTH Cache Corruption
Title source: manualDescription
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it against self._data_len, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to send a TXT, HINFO, or A/AAAA record with rdlength=65535 and seed DNSCache and ServiceInfo.properties with truncated, attacker-shaped key/value or address records. This issue is fixed in version 0.149.16.
References (5)
Core 5
Core References
X_Refsource_Misc x_refsource_misc
https://github.com/python-zeroconf/python-zeroconf/issues/1752
X_Refsource_Misc x_refsource_misc
https://github.com/python-zeroconf/python-zeroconf/pull/1756
X_Refsource_Confirm x_refsource_confirm
https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-qc2x-6f54-m6h9
X_Refsource_Misc x_refsource_misc
https://github.com/python-zeroconf/python-zeroconf/commit/544449596e645fcaad3834fa0cb614a54f847a82
X_Refsource_Misc x_refsource_misc
https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.16
Scores
CVSS v4
5.3
EPSS
0.0020
EPSS Percentile
10.5%
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-130
Status
published
Products (1)
python-zeroconf/python-zeroconf
< 0.149.16
Published
Jul 17, 2026
Tracked Since
Jul 18, 2026