CVE-2026-107885: CWE-770 Allocation of Resources Without Limits or Throttling in OpenPrinting CUPS
Description
CVE-2026-107885 is a resource-exhaustion vulnerability in OpenPrinting CUPS versions up to 2.4.20. It arises from improper handling of job submission timeouts in the cupsdCheckJobs() function, where timeout processing is suppressed for all pending jobs if any client connection has an ongoing Send-Document operation. This allows a client to hold an incomplete HTTP request, preventing unrelated jobs from timing out and causing accumulation of incomplete jobs until the MaxJobs limit is reached, which blocks new legitimate print submissions.
CVSS v3.1
Score 3.3low
Affected software
OpenPrinting
CUPS
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
OpenPrinting CUPS through version 2.4.20 contains a resource exhaustion vulnerability due to the scheduler suppressing timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation. The suppression does not verify if the connection corresponds to the job being checked, allowing a client with access to the IPP service to hold an incomplete HTTP request with Send-Document headers before authorization. This prevents unrelated incomplete jobs from expiring, leading to accumulation of incomplete jobs until the MaxJobs limit is exhausted, resulting in denial of service for further print submissions. The suppression ends when the held connection closes.
Potential Impact
The vulnerability can cause denial of service by exhausting the MaxJobs resource limit, preventing legitimate print jobs from being submitted. There is no impact on confidentiality or integrity, only availability is affected. The CVSS score is 3.3 (low severity), reflecting limited impact and requiring local or low-privilege access with no user interaction.
Mitigation Recommendations
No official patch or fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider restricting access to the IPP service to trusted clients to reduce risk of exploitation. Monitor for unusual accumulation of incomplete print jobs and close stale client connections to mitigate resource exhaustion.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-10-09T03:54:15.382Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac867aa2cdf04f6561586a6
Added to database: 10/09/2026, 04:03:54 UTC
Last enriched: 10/09/2026, 04:18:18 UTC
Last updated: 10/09/2026, 04:19:07 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.