CVE-2026-107885
Last modified
CVE-2026-107885 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| OpenPrinting | CUPS | <= 2.4.20 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-107885?
How severe is CVE-2026-107885?
How do I fix CVE-2026-107885?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-107852Jexactyl is a customisable game management panel and billing…7.1
- CVE-2026-107854Jexactyl is a customisable game management panel and billing…5.4
- CVE-2026-107856CiviForm simplifies applications for government benefits pro…4.5
- CVE-2026-107857Mindwtr is a free offline-first task management application …4.4
- CVE-2026-10786Improper access control in the ticketing integration setting…6.5
- CVE-2026-10787Missing authorization in the deleted user groups API in Devo…4.3
- CVE-2026-107886OpenPrinting CUPS before 2.4.20 contains a double-free in pr…2.3
- CVE-2026-107888OpenPrinting CUPS before 2.4.20 contains a NULL pointer dere…5.1
- CVE-2026-107889A flaw was found in the login theme rendering component of K…5.5
- CVE-2026-10789A maliciously crafted webpage, when visited by a user with A…9.6
- CVE-2026-107890OpenPrinting CUPS before 2.4.20 contains a NULL pointer dere…3.3
- CVE-2026-1079A native messaging host vulnerability in Pega Browser Extens…6
Are you affected by CVE-2026-107885?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
