CVE-2026-107885
Received Received - Intake

Resource Exhaustion in OpenPrinting CUPS Scheduler

Vulnerability report for CVE-2026-107885, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OpenPrinting CUPS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-107885 is a denial-of-service (DoS) vulnerability in OpenPrinting CUPS versions up to 2.4.20. It occurs in the cupsdCheckJobs() function where an incomplete Send-Document request can globally suppress job submission timeouts for all pending jobs. This happens because the function checks for any active Send-Document operation across all client connections without verifying if the connection is associated with the job being examined. As a result, jobs waiting for documents never expire, allowing an attacker to accumulate jobs until the system reaches MaxJobs (default 500), blocking new print submissions.

The attack requires no authentication and can be executed by sending a valid Send-Document request with a large Content-Length but only partially transmitting the document body, keeping the connection open indefinitely. The DoS persists until the attacker closes the connection.

Detection Guidance

Monitor for unusually high job counts in CUPS logs or via 'lpstat -o' command. Check for incomplete HTTP requests with large Content-Length headers but no document data. Use network monitoring tools to detect connections holding Send-Document headers without completing.

Impact Analysis

If you use a network-accessible shared print server running vulnerable CUPS versions, an attacker could exploit this to block all new print submissions by filling up the job queue. Systems exposing CUPS only on loopback are not remotely exploitable. The impact is denial of service for printing services until the attack stops.

Compliance Impact

This vulnerability primarily causes a denial-of-service (DoS) condition by exhausting system resources, which could indirectly impact compliance with standards like GDPR or HIPAA by disrupting availability of critical services. For example, if a print server is unavailable due to this DoS, it may affect data processing or record-keeping operations subject to these regulations.

Mitigation Strategies

Upgrade CUPS to the latest version beyond 2.4.20. Restrict network access to CUPS ports (631/tcp) using firewalls. Disable remote job submission if not needed. Monitor job queues for unexpected growth.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107885. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart