Known vulnerabilities in cups

Software: cups
Software CPE: cpe:2.3:a:OpenPrinting:cups:*:*:*:*:*:*:*:*
Total vulnerabilities: 21
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting cups cups is affected by 21 known vulnerabilities: 3 high, 6 medium, 12 low Critical High Medium Low

Vulnerabilities (21)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137378 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-61702
CWE-22 Medium
No
No
2.4.20 13.07.2026 SB2026061742
#VU134734 - Improper Link Resolution Before File Access ('Link Following')
CVE-2026-55480
CWE-59 Low
No
No
2.4.20 17.06.2026 SB2026061742
#VU134733 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-55467
CWE-93 Low
No
No
2.4.20 17.06.2026 SB2026061742
#VU134732 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-55453
CWE-74 Low
No
No
2.4.20 17.06.2026 SB2026061742
#VU126468 - Out-of-bounds read
CVE-2026-41079
CWE-125 Low
No
No
2.4.17 17.04.2026 SB2026041116
SB2026050301
SB2026051341
and 3 more
#VU125824 - Use After Free
CVE-2026-39316
CWE-416 Low
No
No
2.4.17 11.04.2026 SB2026041116
SB2026041540
SB20260417108
and 13 more
#VU125822 - Integer underflow
CVE-2026-39314
CWE-191 Low
No
No
2.4.17 11.04.2026 SB2026041116
SB20260417108
SB20260417109
and 12 more
#VU125820 - Out-of-bounds read
CWE-125 Low
No
No
2.4.17 11.04.2026 SB2026041116
#VU124815 - Improper input validation
CVE-2026-34978
CWE-20 Medium
No
No
- 02.04.2026 -
#VU124814 - Incorrect Authorization
CVE-2026-27447
CWE-863 Low
No
No
- 02.04.2026 -
#VU124813 - Improper input validation
CVE-2026-34980
CWE-20 High
No
No
- 02.04.2026 -
#VU124812 - Heap-based Buffer Overflow
CVE-2026-34979
CWE-122 Medium
No
No
- 02.04.2026 -
#VU124811 - Improper input validation
CVE-2026-34990
CWE-20 Low
No
No
2.4.17 02.04.2026 SB2026040206
SB2026041665
SB20260417108
and 10 more
#VU118818 - Resource exhaustion
CVE-2025-58436
CWE-400 Low
No
No
2.4.15 27.11.2025 SB2025112765
SB2025112856
SB2025120406
and 16 more
#VU118817 - Out-of-bounds write
CVE-2025-61915
CWE-787 Low
No
No
2.4.15 27.11.2025 SB2025112765
SB2025112772
SB2025112855
and 14 more
#VU115165 - NULL Pointer Dereference
CVE-2025-58364
CWE-476 Medium
No
No
2.4.12 11.09.2025 SB2025091140
SB2025091147
SB2025091148
and 18 more
#VU115164 - Improper Authentication
CVE-2025-58060
CWE-287 High
No
No
2.4.13 11.09.2025 SB2025091139
SB2025091141
SB2025091147
and 28 more
#VU92075 - UNIX Symbolic Link (Symlink) Following
CVE-2024-35235
CWE-61 Low
Available
No
2.4.9 13.06.2024 SB2024061389
SB2024061398
SB2024061399
and 29 more
#VU80932 - Off-by-one Error
CVE-2023-4504
CWE-193 High
No
No
2.4.7 20.09.2023 SB2023092051
SB2023092052
SB2023092054
and 26 more
#VU77641 - Use After Free
CVE-2023-34241
CWE-416 Medium
No
No
2.4.6 22.06.2023 SB2023062261
SB2023062272
SB2023062276
and 36 more


Showing elements 1 - 20 out of 21