CVE-2026-44941: libzypp path traversal via "keyhint" in repomd.xml
Published Jul 2, 2026
·Updated
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
Affected Software
2 affected components
libzypp libzypp<17.38.12
openSUSE Libzypp<17.38.12
Remediation
Event History
Jul 2, 2026
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-44941?
The severity of CVE-2026-44941 is rated as high with a score of 8.4.
2
How do I fix CVE-2026-44941?
To fix CVE-2026-44941, upgrade libzypp to version 17.38.12 or later.
3
What type of vulnerability is CVE-2026-44941?
CVE-2026-44941 is a path traversal vulnerability.
4
What can attackers do with CVE-2026-44941?
Attackers can use CVE-2026-44941 to inject or overwrite files on the target system as root.
5
In which software is CVE-2026-44941 found?
CVE-2026-44941 is found in libzypp prior to version 17.38.12.