← Vulnerability feed

Vulnerability record · CVE-2026-34933 · published 3 April 2026

CVE-2026-34933: Avahi vulnerability

Avahi · Avahi

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.

5.5 CVSS 3.1 Medium EPSS 0.16% · top 95.4% CWE-617 · CWE-617
5.5CVSS 3.1 base score
0.16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
5References, 3 tagged exploit
24 Jul 2026Last modified by NVD

Description

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-rc4.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-34933 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2017-6519Avahi origin validation error vulnerabilityavahi-daemon in Avahi through 0.6.32 and 0.7 inadvertently responds to IPv6 unicast queries with source addresses that are not on-link, which allows …EPSS 3.2%7.8CVE-2021-26720Avahi link following vulnerabilityavahi-daemon-check-dns.sh in the Debian avahi package through 0.8-4 is executed as root via /etc/network/if-up.d/avahi-daemon, and allows a local att…EPSS 0.40%6.5CVE-2026-24401Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions 0.9rc2 and below, avahi-daem…EPSS 0.30%6.5CVE-2025-68468Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can…EPSS 0.39%6.5CVE-2025-68471Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can…EPSS 0.41%5.5CVE-2025-68276Avahi vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, an unprivileged …EPSS 0.16%5.5CVE-2025-59529Avahi uncontrolled resource consumption vulnerabilityAvahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In versions up to and including 0.9-rc2,…EPSS 0.18%5.5CVE-2023-38473Avahi vulnerabilityA vulnerability was found in Avahi. A reachable assertion exists in the avahi_alternative_host_name() function.EPSS 0.32%

Source: NIST National Vulnerability Database (record CVE-2026-34933), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.