Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:brew/airshare

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability in the Airshare zeroconf component allows unauthenticated LAN-local attackers to cause memory exhaustion by sending malformed mDNS packets. The issue arises from unbounded storage of exception deduplication state that retains large packet buffers, leading to potential out-of-memory conditions and service degradation on affected devices. The flaw is fixed in zeroconf version 0.149.6. No in-process workaround exists; upgrading or restricting mDNS traffic to trusted segments is recommended.

Join the discussion

The Airshare zeroconf component has an unbounded DNS record cache vulnerability (CVE-2026-47184) that allows any unauthenticated host on the local network to exhaust memory via multicast DNS floods. This occurs because the DNS cache inserts every response record without limiting the number of entries, causing memory exhaustion and degraded performance on affected devices. The issue is fixed in zeroconf version 0.149.6. No in-process workaround exists; network-level restrictions on mDNS traffic are recommended until upgrading.

Join the discussion

A vulnerability in python-zeroconf prior to version 0.149.12 allows unauthenticated local network attackers to cause memory exhaustion and CPU resource starvation by sending spoofed truncated mDNS queries. This leads to denial of service conditions such as process crashes or degraded zeroconf functionality on affected devices. The issue is fixed in version 0.149.12.

Join the discussion

A vulnerability in the Airshare zeroconf Python library allows unauthenticated local network hosts to inject malformed mDNS records with over-advertised length fields, causing cache corruption. This occurs because the parser reads record lengths without validating against the actual data buffer size, leading to desynchronization of parser state and insertion of attacker-shaped records into the cache. The issue affects versions prior to 0.149.16 and is fixed in that version. The vulnerability does not allow remote code execution or denial of service but can poison the local mDNS cache, potentially impacting downstream services relying on zeroconf discovery.

Join the discussion

The Airshare product includes a vulnerable version of the aiohttp dependency, which relies on llhttp 8.1.1. This version of llhttp is affected by two request smuggling vulnerabilities. The vulnerabilities have not been publicly detailed yet. The issue is resolved by upgrading to llhttp version 9 or higher, which is included starting with aiohttp 3.8.6. The affected Airshare versions are from 0.1.5 up to but not including 0.1.6_7.

Join the discussion

### Impact `DNSIncoming._decode_labels_at_offset` recurses once per DNS-name compression pointer (RFC 1035 §4.1.4). Pointer cycles and label counts were capped, but the chain length of unique forward pointers was not. A single ~3 kB mDNS packet carrying ~1500 chained pointers drives the recursion past CPython's default limit, and `RecursionError` was not listed in `DECODE_EXCEPTIONS`, so it escaped `DNSIncoming.__init__` and was logged by asyncio's default exception handler. Any unauthenticated host on the local link (UDP/5353, `224.0.0.251` / `ff02::fb`) can degrade the mDNS listener; that includes a guest on the same Wi-Fi, a compromised IoT device, or a container on a shared bridge. Replaying at a few hertz produces sustained CPU burn and log flooding, and mDNS-dependent features (HomeKit, Chromecast/Matter, AirPlay, printers) degrade while the attack is in flight. ### Patches Fixed in `zeroconf` 0.149.5 ([PR #1719](https://github.com/python-zeroconf/python-zeroconf/pull/1719)). Upgrade to `>= 0.149.5`. ### Workarounds There is no in-process workaround; upgrading is the fix. Otherwise, restrict mDNS (UDP/5353) to trusted Layer-2 segments via AP client isolation, guest-network separation, or host firewall rules. ### Resources - [PR #1719](https://github.com/python-zeroconf/python-zeroconf/pull/1719), fix - [Issue #1713](https://github.com/python-zeroconf/python-zeroconf/issues/1713), public tracking issue - [RFC 1035 §4.1.4](https://www.rfc-editor.org/rfc/rfc1035#section-4.1.4), [RFC 6762](https://www.rfc-editor.org/rfc/rfc6762), [CWE-674](https://cwe.mitre.org/data/definitions/674.html)

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:brew/airshare
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses