VendorsopenSUSElibzyppall versions
Vulnerabilities

openSUSE libzypp

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2017-9269
lack of keypinning in libzypp could lead to repository switching
Published 2018-03-01 · Modified
9.8EPSS 0.022
CVE-2017-7435
libzypp accepts unsigned 3rd party repo without warning
Published 2018-03-01 · Modified
9.3EPSS 0.018
CVE-2017-7436
libzypp accepts unsigned packages even when configured to check signatures
Published 2018-03-01 · Modified
9.3EPSS 0.018
CVE-2026-25707
Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp
Published 2026-06-29 · Analyzed
8.8EPSS 0.006
CVE-2026-44941
libzypp path traversal via "keyhint" in repomd.xml
Published 2026-07-02 · Analyzed
8.8EPSS 0.005
CVE-2018-7685
libzypp does not reevaluate malicious rpms once downloaded
Published 2018-08-31 · Modified
7.8EPSS 0.003
CVE-2019-18900
libzypp stores cookies world readable
Published 2020-01-24 · Modified
4.0EPSS 0.003