VDB
CVE-2026-44942
CVE-2026-44942
PUBLISHED
CVSS 6.5 MEDIUM
Reported by suse · Published June 18, 2026
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SUSE | libzypp | 17.0.0, 0 |
| SUSE | libzypp | 17.0.0, 0 |
Timeline
- Jun 9, 2026 CVE Published
- Jun 19, 2026 Coalition ESS Score
- Jun 23, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 25, 2026 EPSS Score
- Aug 27, 2026 EPSS Score
- Aug 31, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score