<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T13:42:21.280014+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-05582</id>
    <title>bdu:2026-05582</title>
    <updated>2026-10-03T13:42:21.456430+00:00</updated>
    <content>bdu:2026-05582</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-05582"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-34978</id>
    <title>BELL-CVE-2026-34978</title>
    <updated>2026-10-03T13:42:21.456472+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: cups, Alpaquita:25: cups, Alpaquita:stream: cups</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-34978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0463</id>
    <title>certfr-2026-avi-0463 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
    <updated>2026-10-03T13:42:21.456504+00:00</updated>
    <content>certfr-2026-avi-0463</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0463"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-280405</id>
    <title>EUVD-2026-280405</title>
    <updated>2026-10-03T13:42:21.456522+00:00</updated>
    <content>EUVD-2026-280405</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-280405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34978</id>
    <title>fkie_cve-2026-34978</title>
    <updated>2026-10-03T13:42:21.456533+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-34978</id>
    <title>msrc_CVE-2026-34978 — OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering o…</title>
    <updated>2026-10-03T13:42:21.456560+00:00</updated>
    <content>msrc_CVE-2026-34978</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-34978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1932</id>
    <title>OESA-2026-1932 — cups security update</title>
    <updated>2026-10-03T13:42:21.456577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: cups</p>
<p>CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.

Security Fix(es):</p>
<p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.(CVE-2026-27447)</p>
<p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1932"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10589-1</id>
    <title>openSUSE-SU-2026:10589-1 — cups-2.4.17-1.1 on GA media</title>
    <updated>2026-10-03T13:42:21.456624+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cups-2.4.17-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10589-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:8814</id>
    <title>RHSA-2026:8814 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-03T13:42:21.456662+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cups: CUPS-Filters: Information disclosure and data corruption via crafted TIFF image file processing cups: Authentication Bypass in CUPS Authorization Handling cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS cups: Slow client communication leads to a possible DoS attack cups: cups-filters: cups-filters: Out-of-bounds write via crafted PDF MediaBox cups: OpenPrinting CUPS: Authorization bypass via case-insensitive username comparison cups: OpenPrinting CUPS: Denial of Service via path traversal in RSS notifier cups: OpenPrinting CUPS: Denial of Service via heap-based buffer overflow in job attribute processing cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network cups: OpenPrinting CUPS: Privilege escalation via arbitrary file overwrite due to coerced authentication cups: CUPS: Denial of Service via integer underflow in IPP attribute handling cups: CUPS: Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:8814"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:21787-1</id>
    <title>SUSE-SU-2026:21787-1 — Security update for cups</title>
    <updated>2026-10-03T13:42:21.456699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for cups</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:21787-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34978</id>
    <title>UBUNTU-CVE-2026-34978</title>
    <updated>2026-10-03T13:42:21.456718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: cups, Ubuntu:Pro:18.04:LTS: cups, Ubuntu:Pro:20.04:LTS: cups, Ubuntu:22.04:LTS: cups, Ubuntu:24.04:LTS: cups, Ubuntu:25.10: cups, Ubuntu:26.04:LTS: cups</p>
<p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34978"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0947</id>
    <title>WID-SEC-W-2026-0947 — CUPS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T13:42:21.456750+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CUPS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen, erweiterte Rechte zu erlangen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0947"/>
  </entry>
</feed>
