CVE-2026-25707
published 2026-06-29CVE-2026-25707: A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories…
PriorityP348high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.60%
46.0th percentile
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | libzypp | < 17.38.10 | 17.38.10 |
| suse | libzypp | < 17.38.10 | 17.38.10 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading
ghsa_unreviewed·2026-06-29
CVE-2026-25707 [HIGH] CWE-23 A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Red Hat
libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing
vendor_redhat·2026-06-29·CVSS 8.8
CVE-2026-25707 [HIGH] CWE-22 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing
libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
A flaw was found in libzypp. A remote attacker could exploit a relative path traversal vulnerability when processing repository metadata. By supplying malicious repositories, an attacker could overwrite arbitrary files on the system. This could lead to privilege escalation or a denial of service.
Statement: Important: A path traversal vulnerability in libzypp allows remote attackers to overwrite arbitrary files on the system by supplying maliciou
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-25707 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing [fedora-all]
bugzilla·2026-07-30·CVSS 8.8
CVE-2026-25707 [HIGH] CVE-2026-25707 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing [fedora-all]
CVE-2026-25707 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Bugzilla
CVE-2026-25707 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing
bugzilla·2026-06-29·CVSS 8.8
CVE-2026-25707 [HIGH] CVE-2026-25707 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing
CVE-2026-25707 libzypp: libzypp: Privilege escalation via relative path traversal in repository metadata processing
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
2026-06-29
Published