Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

OpenPrinting — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting OpenPrinting. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenPrinting provides essential open-source printing software, primarily CUPS, which serves as the standard printing system for Linux and macOS. Its core function involves managing print queues, drivers, and network printing protocols, making it a critical infrastructure component for enterprise and consumer devices. Historically, vulnerabilities in this ecosystem have frequently involved remote code execution, buffer overflows, and privilege escalation, often stemming from complex parsing of PostScript or PDF files. Notable incidents include critical flaws allowing unauthenticated attackers to execute arbitrary commands or crash the system via malformed print jobs. While the project maintains an active security response process, the sheer volume of 25 recorded CVEs highlights the inherent risks in handling diverse, legacy printer protocols. These weaknesses underscore the necessity for rigorous input validation and regular patching to prevent exploitation in networked environments where printing services are exposed.

Found 16 results / 25 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-41079 OpenPrinting CUPS: Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users — cups CWE-125 4.3 Medium 2026-04-24
CVE-2026-39316 CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer — cups CWE-416 4.0 Medium 2026-04-07
CVE-2026-39314 CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported` — cups CWE-191 4.0 Medium 2026-04-07
CVE-2026-34980 OpenPrinting CUPS: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network — cups CWE-20 9.8AI Critical AI 2026-04-03
CVE-2026-34979 OpenPrinting CUPS: Heap overflow in `get_options()` — cups CWE-122 5.3 Medium 2026-04-03
CVE-2026-34978 OpenPrinting CUPS: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) — cups CWE-22 6.5 Medium 2026-04-03
CVE-2026-34990 OpenPrinting CUPS: Local print admin token disclosure using temporary printers — cups CWE-287 7.8AI High AI 2026-04-03
CVE-2026-27447 OpenPrinting CUPS: Authorization bypass via case-insensitive group-member lookup — cups CWE-863 4.8 Medium 2026-04-03
CVE-2025-58436 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack — cups CWE-400 5.1 Medium 2025-11-29
CVE-2025-61915 OpenPrinting CUPS vulnerable to stack based out-of-bound write — cups CWE-129 6.0 Medium 2025-11-29
CVE-2025-58364 cups: Remote DoS via null dereference — cups CWE-20 6.5 Medium 2025-09-11
CVE-2025-58060 cups has Authentication bypass with AuthType Negotiate — cups CWE-287 8.0 High 2025-09-11
CVE-2024-35235 Cupsd Listen arbitrary chmod 0140777 — cups CWE-59 4.4 Medium 2024-06-11
CVE-2023-4504 OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow — CUPS CWE-122 7.8 - 2023-09-21
CVE-2023-34241 CUPS vulnerable to use-after-free in cupsdAcceptClient() — cups CWE-416 5.3 Medium 2023-06-22
CVE-2023-32324 OpenPrinting CUPS vulnerable to heap buffer overflow — cups CWE-122 7.5 High 2023-06-01

This page lists every published CVE security advisory associated with OpenPrinting. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.