According to Zdenek Dohnal's post on the oss-sec mailing list, dated October 5, 2026, the CUPS maintainers reassessed their security policies because of the large volume of reports and the long queues at the GitHub CNA. The text says vulnerabilities with a CVSS score above 7.0 will be embargoed and announced on the appropriate security lists. Vulnerabilities scoring below 7.0 will receive a GHSA identifier, have their fix sent, and have the advisory published without embargo. A third point concerns the long queue for obtaining a CVE ID, but the available excerpt is truncated, so it cannot be described in detail. Version 2.4.20 is expected to include several security fixes; the source does not list which flaws are covered or release dates. To verify, consult the original post on the oss-sec list, the CUPS project page, and the 2.4.20 release notes once they are available. Relevance: this case does not involve a Rota Nacional feature. For organizations running CUPS-based printers or print servers, the practical recommendation is to follow advisories, plan the update as soon as the version is released, and keep an inventory of affected systems. If your team uses AI to study this material, do not paste internal logs, user names, e-mail addresses or device identifiers; the platform applies its policy to detected personal data before models run, but manual review remains necessary.
Cyber ·
CUPS 2.4.20 will bring security fixes and a new disclosure policy
CUPS maintainers announced a vulnerability disclosure policy and said version 2.4.20 will include several security fixes, according to an oss-sec mailing list post dated October 5, 2026.
Rota Nacional
Bring privacy into your workflow.
30 days, no card, with a starting quota. After that, Pix credit from R$ 10,00.