VDB

CVE-2026-44941

CVE-2026-44941 PUBLISHED CVSS 8.4 HIGH

Reported by suse · Published July 2, 2026

A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.

Risk Scores

CVSS 3.1
8.4
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersions
SUSElibzypp0
SUSElibzypp0, 0, 0

Timeline

  • Jun 9, 2026 CVE Published
  • Jul 3, 2026 EPSS Score
  • Jul 4, 2026 Coalition ESS Score
  • Jul 6, 2026 Security Advisory
  • Jul 7, 2026 CVE Updated
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score

References

  • issue-tracking
  • patch
Open in Interactive Console →
$ Console Community · 100/wk Open console ›