All 7 CVE vulnerabilities found in libzypp, with AI-generated Chinese analysis, references, and POCs.
Vendor: SUSE
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-44941 | libzypp path traversal via "keyhint" in repomd.xml CWE-23 | 8.4 | High | 2026-07-02 |
| CVE-2026-25707 | Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp CWE-23 | 8.8 | High | 2026-06-29 |
| CVE-2026-44942 | libzypp .repo files can have an optional path which can lead to path traversal attacks CWE-24 | 6.5 | Medium | 2026-06-18 |
| CVE-2018-7685 | libzypp does not reevaluate malicious rpms once downloaded CWE-358 | 9.8 | - | 2018-08-31 |
| CVE-2017-7435 | libzypp accepts unsigned 3rd party repo without warning | 8.1 | - | 2018-03-01 |
| CVE-2017-7436 | libzypp accepts unsigned packages even when configured to check signatures | 8.1 | - | 2018-03-01 |
| CVE-2017-9269 | lack of keypinning in libzypp could lead to repository switching | 9.8 | - | 2018-03-01 |
All 7 known CVE vulnerabilities affecting libzypp with full Chinese analysis, references, and POCs where available.