CVE-2026-47180

Name
CVE-2026-47180
Description
Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS packet carrying chained pointers can trigger a RecursionError that escapes DNSIncoming.__init__, causing sustained CPU burn, log flooding, and degraded mDNS-dependent features for unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb). This issue is fixed in version 0.149.5.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/python-zeroconf/python-zeroconf/commit/f9e23592137f30fdf7ef710dba065da31c79b1cf
security-advisories@github.com https://github.com/python-zeroconf/python-zeroconf/pull/1719
security-advisories@github.com https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.5
security-advisories@github.com https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9pgc-3ccv-5297

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:paulsm:zeroconf:*:*:*:*:*:python:*:* py3-zeroconf >= None < 0.149.5

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-zeroconf edge-community 0.147.2-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
py3-zeroconf edge-community 0.147.2-r0 Achill Gilgenast <achill@achill.org> possibly vulnerable
py3-zeroconf edge-community 0.147.0-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable
py3-zeroconf edge-community 0.147.0-r0 fossdd <fossdd@pwned.life> possibly vulnerable
py3-zeroconf edge-community 0.146.5-r0 fossdd <fossdd@pwned.life> possibly vulnerable
py3-zeroconf edge-community 0.146.3-r0 fossdd <fossdd@pwned.life> possibly vulnerable
py3-zeroconf edge-community 0.144.1-r0 fossdd <fossdd@pwned.life> possibly vulnerable
py3-zeroconf edge-community 0.132.2-r0 Fabian Affolter <fabian@affolter-engineering.ch> possibly vulnerable
py3-zeroconf 3.24-community 0.147.2-r1 Achill Gilgenast <achill@achill.org> possibly vulnerable