Known Vulnerabilities for CUPS by OpenPrinting
Listed below are 10 of the newest known vulnerabilities associated with "CUPS" by "OpenPrinting".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-107890 json | OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation request... | Not Provided | 2026-10-09 | 2026-10-09 |
| CVE-2026-107888 json | OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create ... | Not Provided | 2026-10-09 | 2026-10-09 |
| CVE-2026-107886 json | OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an ex... | Not Provided | 2026-10-09 | 2026-10-09 |
| CVE-2026-107885 json | OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdChec... | Not Provided | 2026-10-09 | 2026-10-09 |
| CVE-2026-105326 json | An argument injection flaw was found in CUPS. When email notification is configured, the CUPS scheduler accepts printer subsc... | Not Provided | 2026-10-05 | 2026-10-07 |
| CVE-2026-95511 json | Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGr... | Not Provided | 2026-09-22 | 2026-09-22 |
| CVE-2026-87876 json | Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printe... | Not Provided | 2026-09-09 | 2026-09-21 |
| CVE-2026-87875 json | The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source... | Not Provided | 2026-09-09 | 2026-09-11 |
| CVE-2026-64612 json | A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installin... | Not Provided | 2026-07-20 | 2026-08-24 |
| CVE-2026-41079 json | Not Provided | 2026-04-24 | 2026-04-27 |