Improper Handling of Length Parameter Inconsistency Affecting zeroconf package, versions [,0.149.16)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (11th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PYTHON-ZEROCONF-17423205
  • published23 Jun 2026
  • disclosed22 Jun 2026
  • creditUnknown

Introduced: 22 Jun 2026

CVE-2026-48487  (opens in a new tab)
CWE-130  (opens in a new tab)

How to fix?

Upgrade zeroconf to version 0.149.16 or higher.

Overview

zeroconf is a Pure Python Multicast DNS Service Discovery Library (Bonjour/Avahi compatible)

Affected versions of this package are vulnerable to Improper Handling of Length Parameter Inconsistency via the _read_character_string and _read_string functions. An attacker can inject malicious key/value or address records into the cache by sending a crafted mDNS packet with an over-advertised rdlength field, causing downstream consumers to trust attacker-controlled data.

Note: This can be exploited by any unauthenticated host on the local network segment via multicast mDNS responses.

Workaround

This vulnerability can be mitigated by restricting mDNS (UDP/5353) to trusted Layer-2 segments using AP client isolation, guest-network separation, or host firewall rules.

CVSS Base Scores

version 4.0
version 3.1