A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service or privilege escalation.
{
"cna_assigner": "suse",
"cwe_ids": [
"CWE-23"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25707.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "17.38.10"
}
],
"cpe": "cpe:2.3:a:opensuse:libzypp:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
[
{
"target": {
"function": "ContentFileReader::parse",
"file": "zypp/zypp/parser/susetags/ContentFileReader.cc"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/opensuse/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b",
"digest": {
"function_hash": "9993119882200258114496118543836246903",
"length": 1878.0
},
"id": "CVE-2026-25707-38398d31"
},
{
"target": {
"file": "zypp/zypp/parser/yum/RepomdFileReader.cc"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/opensuse/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b",
"digest": {
"threshold": 0.9,
"line_hashes": [
"175816485434308815400672742786488143453",
"51179667140839378840421469717821812807",
"227097185888369506580927304068146910152",
"337100025534180423322368980431408493411",
"19460046615771205051021114939239028241",
"135728362831379775272199623303685025419",
"151290842750203244517978011737770419968",
"25969048447627102836829276323446105055",
"292090575802367758628447078086748940743",
"99691571550810668386614699806148591061",
"335720979053903933477401395257969385892",
"8384947147479140101005795967780477597",
"33539529151441287882820126802845303851",
"290800810949749554806798125705371903143",
"248627162430504924922469930642427641246",
"70801818374507228359197244263686682482",
"289652854311511241784208251042753005363",
"225760989206331997566009452571606169940",
"90930838358729371414319554497815436660",
"143329022466338373197947031028830750790",
"200250847861693880964063068804569598013",
"99690183134219073791713098608241511565",
"338401966175685891233055771028655678851",
"307173674332162595546901942320486452356",
"289261342422641145893087056573353208798"
]
},
"id": "CVE-2026-25707-995e4007"
},
{
"target": {
"file": "zypp/zypp/parser/susetags/ContentFileReader.cc"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/opensuse/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b",
"digest": {
"threshold": 0.9,
"line_hashes": [
"120479660747147485705038646029298466355",
"232040927986857053645926765228481516024",
"262458386381125516573243307753808534098",
"37611305119533734236659926900395484322",
"243331414410620818311655895831250026480",
"281933355199770106927889470173725802840",
"88038106254434253278043788615212113286",
"106057586156350196872185886208941933333",
"26280184441186734097822566446636762503",
"131727279539312165505849438150090082250",
"256446032529602135478011742188545861050",
"211473514419839170498534182048849853676",
"117471994089917384101265001864072397248",
"260446929096051779059478175866306334560",
"304986860892276912429581206316776745594",
"318316593627512342837308896133009567798",
"196106346248759440507207698452458168122"
]
},
"id": "CVE-2026-25707-ad4c4f19"
},
{
"target": {
"function": "RepomdFileReader::Impl::consumeNode",
"file": "zypp/zypp/parser/yum/RepomdFileReader.cc"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/opensuse/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b",
"digest": {
"function_hash": "336509112188551936415069004740936442637",
"length": 1380.0
},
"id": "CVE-2026-25707-b11cd87d"
}
]
"2026-08-12T15:31:59Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25707.json"