© 2025-2026 PySpect
First version without a known vulnerability: 0.149.16
zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet
Fixed in: 0.149.16
python-zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood
Fixed in: 0.149.12
zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
Fixed in: 0.149.7
zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
Fixed in: 0.149.6
zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
Fixed in: 0.149.5