CVE-2025-58060

Published Sep 11, 2025

Last updated a year ago

Overview

Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to anything but `Basic`, if the request contains an `Authorization: Basic ...` header, the password is not checked. This results in authentication bypass. Any configuration that allows an `AuthType` that is not `Basic` is affected. Version 2.4.13 fixes the issue.
Source
security-advisories@github.com
NVD status
Analyzed
Products
cups

Risk scores

CVSS 3.1

Type
Secondary
Base score
8
Impact score
5.5
Exploitability score
2.5
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-287

Social media

Hype score
Not currently trending
  1. The #SUSE CUPS vulnerability (CVE-2025-58060) is a textbook case of legacy complexity haunting modern infrastructure. Heap overflow, local to root pivot, and it affects the IPP stack. Read more: 👉 https://t.co/1RXppOAV8z #Security https://t.co/Mz6uXMhMJW

    @Cezar_H_Linux

    11 Feb 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-58060: CUPS: Authentication bypass with AuthType Negotiate https://t.co/mAvLgwKphE CVE-2025-58364: CUPS: Remote DoS via null dereference https://t.co/VOuFIts4Iy

    @oss_security

    17 Sept 2025

    132 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🚨 Vulnerabilidad de CUPS en Linux permite a atacantes realizar ataques DoS remotos y eludir la autenticación ➡️ Linux Common Unix Printing System (CUPS) ⚠️ CVE-2025-58364 ⚠️ CVE-2025-58060 https://t.co/jHsB1LZ1Sf https://t.co/g0KsAen9FI

    @elhackernet

    16 Sept 2025

    2294 Impressions

    10 Retweets

    28 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️ Linux CUPS Alert! Two new flaws (CVE-2025-58364 & CVE-2025-58060) let attackers crash printing services 🖨️ & bypass admin authentication 🔑. Block port 631 + disable auto-discovery until patches drop! 🔗 https://t.co/LKZM6ZLCXq #Linux #CUPS #CyberSecurity

    @VaultEdgeIT

    15 Sept 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 📢 𝐍𝐞𝐰 𝐂𝐕𝐄 𝐚𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐣𝐮𝐬𝐭 𝐝𝐫𝐨𝐩𝐩𝐞𝐝! CUPS on Linux is vulnerable to critical exploits-learn how CVE-2025-58060 and CVE-2025-58364 can crash services or bypass authentication entirely. 👉 Dive into the fu

    @PurpleOps_io

    15 Sept 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CUPSに2つの重大な脆弱性(CVE-2025-58364とCVE-2025-58060)が発見され、Linuxシステムがリモート攻撃にさらされています。CVE-2025-58364はサービス妨害を引き起こし、CVE-2025-58060は認証バイパスを可能にします。両者と

    @cyber_edu_jp

    15 Sept 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🗣️ CUPS Flaws Allow Linux Remote DoS (CVE-2025-58364) and Authentication Bypass (CVE-2025-58060) https://t.co/ykg6KfY7L3

    @fridaysecurity

    15 Sept 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. URGENT: #SUSE patches critical CUPS flaws in SLES 12 SP5. CVE-2025-58060 (Auth Bypass, CVSS 8.0) CVE-2025-58364 (DoS, CVSS 6.5) Patch immediately to protect print servers from remote exploitation. Read more:👉 https://t.co/flcFivXlgV #Security https://t.co/2EfViVmn97

    @Cezar_H_Linux

    13 Sept 2025

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2025-58060 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the `AuthType` is set to any… https://t.co/2NmqQawcNV

    @CVEnew

    11 Sept 2025

    512 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations