CVE-2026-56004: Opensuse Buildservice

Critical severity, CVSS 10.0. EPSS: 0.7% chance of exploitation in the next 30 days.

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services

Affected products

  • Opensuse Buildservice: before 0.12.4 (fixed in 0.12.4)

Published 2026-07-02. Last modified 2026-07-02.