{"id":"CVE-2026-47180","aliases":["GHSA-9pgc-3ccv-5297","PYSEC-2026-3436"],"url":"https://o3.security/vulnerability/CVE-2026-47180","summary":"Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service","details":"Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS packet carrying chained pointers can trigger a RecursionError that escapes DNSIncoming.__init__, causing sustained CPU burn, log flooding, and degraded mDNS-dependent features for unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb). This issue is fixed in version 0.149.5.","published":"2026-07-17T18:21:25.199Z","modified":"2026-08-19T03:48:18.124161612Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00226,"percentile":0.1361,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"zeroconf","fixedVersion":"0.149.5"}],"fix":{"url":"https://github.com/python-zeroconf/python-zeroconf/commit/f9e23592137f30fdf7ef710dba065da31c79b1cf","label":"python-zeroconf/python-zeroconf@f9e2359"},"references":[{"type":"WEB","url":"https://github.com/python-zeroconf/python-zeroconf/releases/tag/0.149.5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47180.json"},{"type":"ADVISORY","url":"https://github.com/python-zeroconf/python-zeroconf/security/advisories/GHSA-9pgc-3ccv-5297"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47180"},{"type":"FIX","url":"https://github.com/python-zeroconf/python-zeroconf/commit/f9e23592137f30fdf7ef710dba065da31c79b1cf"},{"type":"FIX","url":"https://github.com/python-zeroconf/python-zeroconf/pull/1719"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T03:48:18.124161612Z"}}