CVE-2024-47850: Cups

High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.

CUPS cups-browsed before 2.5b1 will send an HTTP POST request to an arbitrary destination and port in response to a single IPP UDP packet requesting a printer to be added, a different vulnerability than CVE-2024-47176. (The request is meant to probe the new printer but can be used to create DDoS amplification attacks.)

Affected products

  • Cups Cups: from 1.0, before 2.5b1 (fixed in 2.5b1)

Published 2024-10-04. Last modified 2026-06-17.