VDB

CVE-2026-44942

CVE-2026-44942 PUBLISHED CVSS 6.5 MEDIUM

Reported by suse · Published June 18, 2026

A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
SUSElibzypp17.0.0, 0
SUSElibzypp17.0.0, 0

Timeline

  • Jun 9, 2026 CVE Published
  • Jun 19, 2026 Coalition ESS Score
  • Jun 23, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 25, 2026 EPSS Score
  • Aug 27, 2026 EPSS Score
  • Aug 31, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score

References

  • issue-tracking
  • vendor-advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›