CVE-2026-87875Medium· 4.3▾ TwilightPoC availableThe cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backen…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 23.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Exploit / PoC code exists
Last analysed / modified upstream
0.3%
0.3% → 0.3%
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
cups-main (all versions)cups (all versions)cups (all versions)cups (all versions)cups (all versions)cups (all versions)rhel9/cups (all versions)rhcos/rhcos (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Fixed on upstream master branch with commit 0c6842f and for versions 2.4.x with commit 2b1dc17.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96545Medium· 4.4An out-of-bounds heap read flaw was found in GIMP's TIM image loader
CVE-2026-87876Low· 3.0Two case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS's scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certai…
CVE-2026-96546Low· 2.5A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader
CVE-2026-88840Medium· 5.3BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message.
CVE-2026-88835Medium· 6.1BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap read.
CVE-2025-49796Critical· 9.1A vulnerability was found in libxml2