Libzypp · Libzypp · CVE-2026-25707
**Name of the Vulnerable Software and Affected Versions**
libzypp versions prior to 17.38.10
**Description**
A relative path traversal issue exists when processing repository metadata. Remote attackers can exploit this by supplying malicious repositories to overwrite files on the system, which may result in a denial of service or privilege escalation. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
**Recommendations**
Update to version 17.38.10 or later.