<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 19:44:48 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-05582</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-05582</link>
      <description>bdu:2026-05582</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-05582</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-34978</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-34978</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: cups, Alpaquita:25: cups, Alpaquita:stream: cups&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: cups, Alpaquita:25: cups, Alpaquita:stream: cups&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-34978</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0463 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0463</link>
      <description>certfr-2026-avi-0463</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0463</guid>
    </item>
    <item>
      <title>EUVD-2026-280405</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-280405</link>
      <description>EUVD-2026-280405</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-280405</guid>
    </item>
    <item>
      <title>fkie_cve-2026-34978</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34978</link>
      <description>&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-34978</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-34978 — OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering o…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-34978</link>
      <description>msrc_CVE-2026-34978</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-34978</guid>
    </item>
    <item>
      <title>OESA-2026-1932 — cups security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1932</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: cups&lt;/p&gt;
&lt;p&gt;CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.(CVE-2026-27447)&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: cups&lt;/p&gt;
&lt;p&gt;CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, CUPS daemon (cupsd) contains an authorization bypass vulnerability due to case-insensitive username comparison during authorization checks. The vulnerability allows an unprivileged user to gain unauthorized access to restricted operations by using a user with a username that differs only in case from an authorized user. At time of publication, there are no publicly available patches.(CVE-2026-27447)&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1932</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10589-1 — cups-2.4.17-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10589-1</link>
      <description>&lt;p&gt;cups-2.4.17-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cups-2.4.17-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10589-1</guid>
    </item>
    <item>
      <title>RHSA-2026:8814 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:8814</link>
      <description>&lt;p&gt;cups: CUPS-Filters: Information disclosure and data corruption via crafted TIFF image file processing cups: Authentication Bypass in CUPS Authorization Handling cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS cups: Slow client communication leads to a possible DoS attack cups: cups-filters: cups-filters: Out-of-bounds write via crafted PDF MediaBox cups: OpenPrinting CUPS: Authorization bypass via case-insensitive username comparison cups: OpenPrinting CUPS: Denial of Service via path traversal in RSS notifier cups: OpenPrinting CUPS: Denial of Service via heap-based buffer overflow in job attribute processing cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network cups: OpenPrinting CUPS: Privilege escalation via arbitrary file overwrite due to coerced authentication cups: CUPS: Denial of Service via integer underflow in IPP attribute handling cups: CUPS: Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cups: CUPS-Filters: Information disclosure and data corruption via crafted TIFF image file processing cups: Authentication Bypass in CUPS Authorization Handling cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS cups: Slow client communication leads to a possible DoS attack cups: cups-filters: cups-filters: Out-of-bounds write via crafted PDF MediaBox cups: OpenPrinting CUPS: Authorization bypass via case-insensitive username comparison cups: OpenPrinting CUPS: Denial of Service via path traversal in RSS notifier cups: OpenPrinting CUPS: Denial of Service via heap-based buffer overflow in job attribute processing cups: OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network cups: OpenPrinting CUPS: Privilege escalation via arbitrary file overwrite due to coerced authentication cups: CUPS: Denial of Service via integer underflow in IPP attribute handling cups: CUPS: Denial of Service and potential arbitrary code execution via use-after-free vulnerability when deleting temporary printers.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:8814</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:21787-1 — Security update for cups</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:21787-1</link>
      <description>&lt;p&gt;Security update for cups&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cups&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:21787-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-34978</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34978</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cups, Ubuntu:Pro:18.04:LTS: cups, Ubuntu:Pro:20.04:LTS: cups, Ubuntu:22.04:LTS: cups, Ubuntu:24.04:LTS: cups, Ubuntu:25.10: cups, Ubuntu:26.04:LTS: cups&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cups, Ubuntu:Pro:18.04:LTS: cups, Ubuntu:Pro:20.04:LTS: cups, Ubuntu:22.04:LTS: cups, Ubuntu:24.04:LTS: cups, Ubuntu:25.10: cups, Ubuntu:26.04:LTS: cups&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-34978</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0947 — CUPS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0947</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CUPS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen, erweiterte Rechte zu erlangen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CUPS ausnutzen, um Sicherheitsvorkehrungen zu umgehen, beliebigen Code auszuführen, erweiterte Rechte zu erlangen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0947</guid>
    </item>
  </channel>
</rss>
