CVE-2026-25707
8.8
HIGH
CVSS 3.1
EPSS 0.60%
Description
A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
How to fix CVE-2026-25707
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/libzypp—no fix listed
Is CVE-2026-25707 being exploited?
Low — EPSS is 0.6%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |