Resource Exhaustion Vulnerability in OpenPrinting CUPS Affected by Client Connection Issues
CVE-2026-107885

3.3LOW

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107885?

OpenPrinting's CUPS version 2.4.20 is susceptible to a resource exhaustion vulnerability that arises during the submission-timeout handling of cupsdCheckJobs(). The issue occurs when the print scheduler fails to process timeouts for all pending jobs if there is an active Send-Document operation from any client. This can lead to scenarios where clients exploiting the IPP service can hold incomplete HTTP requests with parsed Send-Document headers, preventing necessary job expirations. As these incomplete jobs accumulate, the maximum job limit can be reached, effectively blocking further legitimate print submissions. Only when the associated client connection is closed does the issue resolve, allowing previously stuck jobs to be processed again.

Affected Version(s)

CUPS 0 <= 2.4.20

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.