Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

cups — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in cups, with AI-generated Chinese analysis, references, and POCs.

This page documents security weaknesses affecting the Common Unix Printing System (CUPS), a widely used printing system software developed by Apple. The content aggregates vulnerability records associated with this specific product, focusing on common weakness types such as buffer overflows, cross-site scripting, and improper access controls. The collection spans a significant historical period, covering data points from early releases in the mid-2000s through to recent updates in the early 2020s, ensuring a comprehensive view of the software's security landscape over time. Visitors to this resource can effectively track vendor advisories issued by Apple and other relevant maintainers regarding security patches and mitigations for CUPS. Users can deepen their understanding of specific weakness classes by examining how they manifest within the context of print system architectures and configuration mechanisms. Additionally, the page allows for detailed lookup of a product’s vulnerability history, enabling security professionals to analyze trends, identify persistent issues, and assess the long-term impact of specific flaws on system stability and confidentiality. This structured approach facilitates better risk management and informed decision-making for administrators responsible for maintaining secure printing environments. By centralizing these details, the page serves as a reference for technical analysts, security researchers, and IT managers who need to evaluate the exposure and remediation status of CUPS installations across various enterprise and home environments.

Vendor: cups

CVE ID Title CVSS Severity Published
CVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users CWE-125 4.3 Medium 2026-04-24
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer CWE-416 4.0 Medium 2026-04-07
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` CWE-191 4.0 Medium 2026-04-07
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network CWE-20 9.8AI Critical AI 2026-04-03
CVE-2026-34979 OpenPrinting CUPS: Heap overflow in `get_options()` CWE-122 5.3 Medium 2026-04-03
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) CWE-22 6.5 Medium 2026-04-03
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers CWE-287 7.8AI High AI 2026-04-03
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup CWE-863 4.8 Medium 2026-04-03
CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack CWE-400 5.1 Medium 2025-11-29
CVE-2025-61915 OpenPrinting CUPS vulnerable to stack based out-of-bound write CWE-129 6.0 Medium 2025-11-29
CVE-2025-58364 cups: Remote DoS via null dereference CWE-20 6.5 Medium 2025-09-11
CVE-2025-58060 cups has Authentication bypass with AuthType Negotiate CWE-287 8.0 High 2025-09-11
CVE-2024-35235 Cupsd Listen arbitrary chmod 0140777 CWE-59 4.4 Medium 2024-06-11
CVE-2023-4504 OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow CWE-122 7.8 - 2023-09-21
CVE-2023-34241 CUPS vulnerable to use-after-free in cupsdAcceptClient() CWE-416 5.3 Medium 2023-06-22
CVE-2023-32324 OpenPrinting CUPS vulnerable to heap buffer overflow CWE-122 7.5 High 2023-06-01
CVE-2012-6094 Apple CUPS 安全漏洞 8.4 - 2019-12-20
CVE-2018-4300 CPUS 信息泄露漏洞 5.9 - 2019-04-03
CVE-2018-6553 AppArmor cupsd Sandbox Bypass Due to Use of Hard Links 8.8 - 2018-08-10

All 19 known CVE vulnerabilities affecting cups with full Chinese analysis, references, and POCs where available.