Opensuse Tumbleweed
633 CVEs tracked. 7 of them are in CISA KEV.
This hub aggregates every CVE we track for Opensuse Tumbleweed, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Opensuse Tumbleweed CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 64 |
| 2024-11 | 24 |
| 2024-12 | 19 |
| 2025-01 | 40 |
| 2025-02 | 18 |
| 2025-03 | 21 |
| 2025-04 | 18 |
| 2025-05 | 8 |
| 2025-06 | 19 |
| 2025-07 | 17 |
| 2025-08 | 11 |
| 2025-09 | 3 |
| 2025-10 | 8 |
| 2025-11 | 2 |
| 2025-12 | 2 |
| 2026-01 | 4 |
| 2026-02 | 1 |
| 2026-03 | 1 |
| 2026-04 | 4 |
| 2026-05 | 2 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 2 |
Severity
How the 633 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical62
- High283
- Medium267
- Low20
Latest CVEs
The 15 most recently published vulnerabilities affecting Opensuse Tumbleweed.
- CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont29.0
- CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont29.0
- CVE-2026-59674LPE from suricata user to root due to chown in %post in suricata packaging—
- CVE-2026-43502net/rds: handle zerocopy send cleanup before the message is queued7.8
- CVE-2026-41051csync2 uses insecure temporary directories when compiled with C99 or later5.0
- CVE-2026-3832Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response3.7
- CVE-2026-3833Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison6.5
- CVE-2026-22008Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with n...3.7
- CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
- CVE-2026-33636LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch647.6
- CVE-2025-22873Improper access to parent directory of root in os3.8
- CVE-2025-11065Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure5.3
- CVE-2025-43904In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.4.2
- CVE-2026-0892Memory safety bugs fixed in Firefox 147 and Thunderbird 1479.8
- CVE-2026-0891Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 1478.1
Product grouping is registry-driven, with AI assist and human review. How it works