High severity8.8NVD Advisory· Published Jun 29, 2026· Updated Jun 30, 2026
CVE-2026-25707
CVE-2026-25707
Description
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/libsolv&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libzypp&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/libzypp&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/zypper&distro=openSUSE%20Leap%2016.0
< 0.7.39-160000.1.1+ 3 more
- (no CPE)range: < 0.7.39-160000.1.1
- (no CPE)range: < 17.38.13-160000.1.1
- (no CPE)range: < 17.38.10-1.1
- (no CPE)range: < 1.14.98-160000.1.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.