CVE-2026-44941
SUSE libzypp
A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or overwrite files in the target system as root.
- CVSS
- 8.8
- EPSS
- 0.52% 41.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.03