CVE-2026-44942
published 2026-06-18CVE-2026-44942: A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.33%
25.0th percentile
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| suse | libzypp | < 16.22.19 | 16.22.19 |
| suse | libzypp | >= 17.0.0 < 17.38.13 | 17.38.13 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the syste
ghsa_unreviewed·2026-06-18
CVE-2026-44942 [MEDIUM] CWE-24 A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the syste
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
VulDB
SUSE libzypp up to 16.22.18/17.38.12 path traversal (EUVD-2026-37871)
vuldb·2026-06-18
CVE-2026-44942 [LOW] SUSE libzypp up to 16.22.18/17.38.12 path traversal (EUVD-2026-37871)
A vulnerability classified as problematic has been found in SUSE libzypp up to 16.22.18/17.38.12. The impacted element is an unknown function. The manipulation leads to path traversal: '../filedir'.
This vulnerability is listed as CVE-2026-44942. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
Red Hat
libzypp: libzypp: Denial of Service via path traversal in .repo file handling
vendor_redhat·2026-06-18·CVSS 6.5
CVE-2026-44942 [MEDIUM] CWE-22 libzypp: libzypp: Denial of Service via path traversal in .repo file handling
libzypp: libzypp: Denial of Service via path traversal in .repo file handling
A flaw was found in libzypp. This path traversal vulnerability, present in the handling of the "path" component within .repo files, could allow attackers to write content to directories outside of the intended zypp cache. This unauthorized writing of data can lead to a Denial of Service (DoS) by filling up disk space on the system.
Statement: This Moderate impact vulnerability in libzypp allows a path traversal when processing specially crafted `.repo` files. An attacker could exploit this flaw to write arbitrary content outside the intended zypp cache, potentially leading to a denial of service by exhausting disk space. This issue affects systems that process untrusted `.repo` files.
Mitigation: Mitigation fo
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44942 libzypp: libzypp: Denial of Service via path traversal in .repo file handling [fedora-all]
bugzilla·2026-06-18
CVE-2026-44942 [MEDIUM] CVE-2026-44942 libzypp: libzypp: Denial of Service via path traversal in .repo file handling [fedora-all]
CVE-2026-44942 libzypp: libzypp: Denial of Service via path traversal in .repo file handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-44942 libzypp: libzypp: Denial of Service via path traversal in .repo file handling
bugzilla·2026-06-18
CVE-2026-44942 [MEDIUM] CVE-2026-44942 libzypp: libzypp: Denial of Service via path traversal in .repo file handling
CVE-2026-44942 libzypp: libzypp: Denial of Service via path traversal in .repo file handling
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
2026-06-18
Published