Libsolv
Vendor:
First CVE: Dec 28, 2018 · Active for 7 years
13
Total CVEs
More Total CVEs than 91% of tracked products
2.6
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Libsolv over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 28, 2018
7 years ago
Most Recent CVE
May 26, 2026
59 days ago
CVE Severity & Scoring
Libsolv13 CVEs
46%
46%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local2 (15.4%)
Network11 (84.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None5 (38.5%)
Unknown0 (0.0%)
Required8 (61.5%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None13 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-48864HIGH A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed data within `.solv` files due to insufficient input validat | May 26, 2026 | 7.8 | 33 | NO | NO |
CVE-2026-9149MEDIUM A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_ad | May 21, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-9150MEDIUM A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. | May 20, 2026 | 6.5 | 30 | NO | NO |
CVE-2019-20387HIGH repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema. | Jan 21, 2020 | 7.5 | 25 | NO | NO |
CVE-2021-33938HIGH Buffer overflow vulnerability in function prune_to_recommended in src/policy.c in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | Sep 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-33930HIGH Buffer overflow vulnerability in function pool_installable_whatprovides in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | Sep 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-33929HIGH Buffer overflow vulnerability in function pool_disabled_solvable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | Sep 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-33928HIGH Buffer overflow vulnerability in function pool_installable in src/repo.h in libsolv before 0.7.17 allows attackers to cause a Denial of Service. | Sep 2, 2021 | 7.5 | 24 | NO | NO |
CVE-2021-44568MEDIUM Two heap-overflow vulnerabilities exist in openSUSE/libsolv libsolv through 13 Dec 2020 in the decisionmap variable via the resolve_dependencies function at src/solver.c (line 1940 | Feb 21, 2022 | 6.5 | 22 | NO | NO |
CVE-2018-20534MEDIUM There is an illegal address access at ext/testcase.c in libsolv.a in libsolv through 0.7.2 that will cause a denial of service. NOTE: third parties dispute this issue stating that | Dec 28, 2018 | 6.5 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Libsolv
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.7.36 | 1 | 7.8 | 0.2% | 0 | 0 |