CVE-2026-56004: Opensuse Buildservice
Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services
Affected products
- Opensuse Buildservice: before 0.12.4 (fixed in 0.12.4)
Published 2026-07-02. Last modified 2026-07-02.