CVE-2026-107885: Low severity OpenPrinting CUPS vulnerability

Published Oct 9, 2026
·
Updated

OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.

Affected Software

1 affected component
OpenPrinting CUPS<=2.4.20

Event History

Oct 9, 2026
CVE Published
via MITRE·03:54 AM
Data Sourced
via MITRE·03:54 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments are exposed if clients can reach the IPP service and Create-Job submission is allowed. An attacker needs only low-privilege network access to the service.

2

What does an attacker need to do to trigger the resource exhaustion?

The attacker holds an incomplete HTTP request with parsed Send-Document headers open before operation authorization. This suppresses timeout processing for unrelated incomplete jobs until the held connection closes.

3

What is the operational impact?

Incomplete jobs can accumulate until MaxJobs is exhausted. At that point, legitimate print submissions are rejected.

4

What can be done if patching is not immediately possible?

Limit access to the IPP service and restrict Create-Job submission where possible. Closing the malicious or stalled Send-Document connection ends the timeout suppression.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203