CVE-2026-107885: Openprinting Cups
Low severity, CVSS 3.3. EPSS: 0.1% chance of exploitation in the next 30 days.
OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.
Affected products
- Openprinting Cups: up to and including 2.4.20
Published 2026-10-09. Last modified 2026-10-09.