{"id":"DEBIAN-CVE-2026-44942","details":"A path traversal in handling the \"path\" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.","modified":"2026-09-01T16:06:45.099913304Z","published":"2026-06-18T14:17:25.903Z","upstream":["CVE-2026-44942"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-44942"}],"affected":[{"package":{"name":"libzypp","ecosystem":"Debian:12","purl":"pkg:deb/debian/libzypp?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.25.7-2.4","17.31.15-1","17.31.16-1","17.31.17-1","17.31.20-1","17.31.21-1","17.31.21-2","17.31.22-1","17.31.23-1","17.31.25-1","17.31.27-1","17.31.28-1","17.31.29-1","17.31.29-1.1~exp1","17.31.31-1","17.31.31-1.1~exp1","17.32.0-1","17.32.0-1~exp1","17.32.1-1","17.32.2-1","17.32.3-1","17.32.5-1","17.32.6-1","17.33.1-1","17.33.1-1~exp","17.33.3-1","17.34.0-1","17.34.0-1~exp","17.34.1-1","17.35.0-1","17.35.0-2","17.35.1-1","17.35.10-1","17.35.11-1","17.35.12-1","17.35.13-1","17.35.14-1","17.35.15-1","17.35.16-1","17.35.18-1","17.35.19-1","17.35.2-1","17.35.3-1","17.35.4-1","17.35.7-1","17.35.8-1","17.35.9-1","17.36.0-1","17.36.1-1","17.36.2-1","17.36.4-1","17.36.5-1","17.36.6-1","17.36.7-1","17.37.16-1","17.37.17-1","17.37.18-1","17.38.1-1","17.38.11-1","17.38.12-1","17.38.13-1","17.38.13-1+sparc64","17.38.14-1","17.38.2-1","17.38.3-1","17.38.4-1","17.38.5-1","17.38.6-1","17.38.7-1","17.38.8-1","17.38.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44942.json"}},{"package":{"name":"libzypp","ecosystem":"Debian:13","purl":"pkg:deb/debian/libzypp?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["17.36.7-1","17.37.16-1","17.37.17-1","17.37.18-1","17.38.1-1","17.38.11-1","17.38.12-1","17.38.13-1","17.38.13-1+sparc64","17.38.14-1","17.38.2-1","17.38.3-1","17.38.4-1","17.38.5-1","17.38.6-1","17.38.7-1","17.38.8-1","17.38.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44942.json"}},{"package":{"name":"libzypp","ecosystem":"Debian:14","purl":"pkg:deb/debian/libzypp?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"17.38.13-1"}]}],"versions":["17.36.7-1","17.37.16-1","17.37.17-1","17.37.18-1","17.38.1-1","17.38.11-1","17.38.12-1","17.38.2-1","17.38.3-1","17.38.4-1","17.38.5-1","17.38.6-1","17.38.7-1","17.38.8-1","17.38.9-1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-44942.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}