HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-25707Published Modified CNA suse

CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
17.38.10
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

Fix available

17.38.10
Patch commits
Affected packages
  • SUSE / libzypp
    < 17.38.10 (from 0)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H