Known Vulnerabilities for CUPS by OpenPrinting

Listed below are 10 of the newest known vulnerabilities associated with "CUPS" by "OpenPrinting".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2026-107890 json OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation request... Not Provided 2026-10-09 2026-10-09
CVE-2026-107888 json OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create ... Not Provided 2026-10-09 2026-10-09
CVE-2026-107886 json OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an ex... Not Provided 2026-10-09 2026-10-09
CVE-2026-107885 json OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdChec... Not Provided 2026-10-09 2026-10-09
CVE-2026-105326 json An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subsc... Not Provided 2026-10-05 2026-10-07
CVE-2026-95511 json Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGr... Not Provided 2026-09-22 2026-09-22
CVE-2026-87876 json Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printe... Not Provided 2026-09-09 2026-09-21
CVE-2026-87875 json The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source... Not Provided 2026-09-09 2026-09-11
CVE-2026-64612 json A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installin... Not Provided 2026-07-20 2026-08-24
CVE-2026-41079 json Not Provided 2026-04-24 2026-04-27

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report