OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, when the AuthType is set to anything but Basic, if the request contains an Authorization: Basic ... header, the password is not checked. This results in authentication bypass. Any configuration that allows an AuthType that is not Basic is affected. Version 2.4.13 fixes the issue.
{
"cwe_ids": [
"CWE-287"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58060.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-58060.json"
"2026-04-14T11:30:32Z"
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"273716230938177953313785311992748259673",
"92386521260343005417693861735643589009",
"107158546563069763322274401735430584915",
"157108054365630463462527904057947491688",
"64681268632403199256611162265020830067",
"178325614230891376260217678751698712977",
"310692027295275001078364988996233046806"
]
},
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/openprinting/cups/commit/eee59dd0b55a0b11b80bda6ca437d60fee5faa09",
"target": {
"file": "cups/cups.h"
},
"id": "CVE-2025-58060-a39766a3",
"deprecated": false
},
{
"digest": {
"function_hash": "161101854988671363650603007211864002538",
"length": 11512.0
},
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/openprinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221",
"target": {
"file": "scheduler/auth.c",
"function": "cupsdAuthorize"
},
"id": "CVE-2025-58060-b088b8ad",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"252342279466869984469687432689811884911",
"224178397817989152176278622935806424142",
"34023814051622481731660481993435543916",
"32886566208854679595142351155717611645",
"77695424112154206107361435810581927774",
"298653031029906115643324305168188129119",
"35827168545682896286695988030117038484",
"115174652598934948060790637798026279729",
"131496716382430400409608407831702171299",
"60729078821255401626836469559924321696"
]
},
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/openprinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221",
"target": {
"file": "scheduler/auth.c"
},
"id": "CVE-2025-58060-b8682118",
"deprecated": false
}
]