VendorsOpenPrintingcupsall versions
Vulnerabilities

OpenPrinting CUPS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2025-58060
cups has Authentication bypass with AuthType Negotiate
Published 2025-09-11 · Modified
8.0EPSS 0.010
CVE-2026-34990
OpenPrinting CUPS: Local print admin token disclosure using temporary printers
Published 2026-04-03 · Analyzed
7.8EPSS 0.002
CVE-2023-32324
OpenPrinting CUPS vulnerable to heap buffer overflow
Published 2023-06-01 · Modified
7.5EPSS 0.015
CVE-2026-34980
OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network
Published 2026-04-03 · Analyzed
7.5EPSS 0.003
CVE-2022-26691
A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
Published 2022-05-26 · Modified
7.2EPSS 0.006
CVE-2023-34241
CUPS vulnerable to use-after-free in cupsdAcceptClient()
Published 2023-06-22 · Modified
7.1EPSS 0.014
CVE-2023-4504
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
Published 2023-09-21 · Modified
7.0EPSS 0.007
CVE-2024-35235
Cupsd Listen arbitrary chmod 0140777
Published 2024-06-11 · Analyzed
6.7EPSS 0.024
CVE-2025-61915
OpenPrinting CUPS vulnerable to stack based out-of-bound write
Published 2025-11-29 · Analyzed
6.7EPSS 0.005
CVE-2025-58364
cups: Remote DoS via null dereference
Published 2025-09-11 · Modified
6.5EPSS 0.011
CVE-2026-34978
OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache)
Published 2026-04-03 · Analyzed
6.5EPSS 0.004
CVE-2026-27447
OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup
Published 2026-04-03 · Analyzed
6.3EPSS 0.003
CVE-2026-39316
CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer
Published 2026-04-07 · Analyzed
6.2EPSS 0.002
CVE-2026-39314
CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported`
Published 2026-04-07 · Analyzed
6.2EPSS 0.002
CVE-2025-58436
OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
Published 2025-11-29 · Analyzed
5.5EPSS 0.002
CVE-2026-41079
OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users
Published 2026-04-24 · Analyzed
5.4EPSS 0.003
CVE-2026-34979
OpenPrinting CUPS: Heap overflow in `get_options()`
Published 2026-04-03 · Analyzed
5.3EPSS 0.004