CVE-2026-44942: medium-severity vulnerability in SUSE libzypp
libzypp .repo files can have an optional path which can lead to path traversal attacks
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
SUSE · libzyppRelated CVEs — SUSE libzypp
In the same product, most dangerous first.
CVE-2017-9269HIGHlack of keypinning in libzypp could lead to repository switchingEPSS 2.2%CVE-2017-7435HIGHlibzypp accepts unsigned 3rd party repo without warningEPSS 1.8%CVE-2017-7436HIGHlibzypp accepts unsigned packages even when configured to check signaturesEPSS 1.8%CVE-2026-25707HIGHHandcrafted repo metadata may cause arbitrary local files to be overwritten by libzyppEPSS 0.6%CVE-2026-44941HIGHlibzypp path traversal via "keyhint" in repomd.xmlEPSS 0.5%CVE-2018-7685HIGHlibzypp does not reevaluate malicious rpms once downloadedEPSS 0.3%