Openprinting maintains a foundational printing infrastructure stack centered on CUPS (Common Unix Printing System) and its associated filter and library components, which integrate deeply into Linux distributions and Unix-like systems as the de facto print-management layer. The vendor's vulnerability footprint, though narrow in product scope, reaches across a prominent segment of the ecosystem given the ubiquity and privileged role of print services in both server and desktop deployments. Vulnerabilities affecting this vendor demonstrate a meaningful share reaching serious severity and frequently acquire public exploit code, reflecting the memory-unsafe nature of filter and parsing components that process untrusted print job data and device inputs. The recurring exposure clusters around memory-safety issues such as out-of-bounds writes and heap-based buffer overflows, alongside improper input validation and authentication weaknesses in filter chains and device communication, patterns that are intrinsic to the complexity of translating diverse document formats and printer protocols. Defenders should treat print-service updates as standard infrastructure maintenance and monitor CUPS deployments for timely patching, as the attack surface spans both local privilege escalation and remote job-submission vectors; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openprinting over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-47076HIGH CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used f | Sep 26, 2024 | 8.6 | 81 | NO | YES |
CVE-2024-47175CRITICAL CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP att | Sep 26, 2024 | 9.8 | 78 | NO | YES |
CVE-2024-47176MEDIUM CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services an | Sep 26, 2024 | 5.3 | 67 | NO | YES |
CVE-2026-34990HIGH OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, a local unprivileged user can coerce cupsd into a | Apr 3, 2026 | 7.8 | 30 | NO | NO |
CVE-2025-58060HIGH OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Bas | Sep 11, 2025 | 8.0 | 30 | NO | NO |
CVE-2026-34980HIGH OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, in a network-exposed cupsd with a shared target q | Apr 3, 2026 | 7.5 | 29 | NO | NO |
CVE-2023-34095CRITICAL cpdb-libs provides frontend and backend libraries for the Common Printing Dialog Backends (CPDB) project. In versions 1.0 through 2.0b4, cpdb-libs is vulnerable to buffer overflows | Jun 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-58364MEDIUM OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of pri | Sep 11, 2025 | 6.5 | 26 | NO | NO |
CVE-2026-34978MEDIUM OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in noti | Apr 3, 2026 | 6.5 | 25 | NO | NO |
CVE-2026-41079MEDIUM OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response t | Apr 24, 2026 | 5.4 | 24 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openprinting.
Media articles that mention a CVE ID that affects a product developed by Openprinting — matched by CVE ID, not by vendor name.