Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107885

Quick assessment

Affected
OpenPrinting CUPS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenPrinting CUPS 2.4.20 及更早版本在 cupsdCheckJobs() 函数的提交超时处理机制中存在资源耗尽漏洞。当任意客户端连接存在正在进行的 Send-Document(发送文档)操作时,调度器会暂停对所有待处理作业的超时处理,且并未将该连接与正在检查的作业进行匹配。 允许访问 IPP 服务的客户端可在操作授权前,持有包含已解析的 Send-Document 头部的未完成 HTTP 请求,从而导致无关的未完成作业无法按预期过期。如果允许执行 Create-Job(创建作业)提交,则未完

CVSS 3.3 · Low
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107885

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OpenPrinting CUPS 0 ~ 2.4.20 -

II. Public POCs for CVE-2026-107885

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107885

请登录查看更多情报信息。

Other References for CVE-2026-107885 (1)

Same Patch Batch · OpenPrinting · 2026-10-09 · 4 CVEs total

CVE-2026-107888 5.1 MEDIUM CUPS<2.4.20空指针解引用致服务终止
CVE-2026-107890 3.3 LOW CUPS漏洞:空指针解引用致服务崩溃
CVE-2026-107886 2.3 LOW CUPS<2.4.20双释放致拒绝服务

IV. Related Vulnerabilities

V. Comments for CVE-2026-107885

No comments yet


Leave a comment