PatchSiren

OpenPrinting CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenPrinting CVE published 2026-04-03

CVE-2026-34978

OpenPrinting CUPS is vulnerable to a path traversal attack in the RSS notifier. Versions 2.4.16 and prior allow a remote IPP client to write RSS XML bytes outside CacheDir/rss. The notifier, running as lp, can replace root-managed state files via temp-file + rename(). This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. System administrators and users of OpenPrinting CUPS should be aware o [truncated]