CVE Tools

Opensuse Tumbleweed

633 CVEs tracked. 7 of them are in CISA KEV.

This hub aggregates every CVE we track for Opensuse Tumbleweed, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Opensuse Tumbleweed CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Opensuse Tumbleweed CVEs per month
MonthCVEs
2024-1064
2024-1124
2024-1219
2025-0140
2025-0218
2025-0321
2025-0418
2025-058
2025-0619
2025-0717
2025-0811
2025-093
2025-108
2025-112
2025-122
2026-014
2026-021
2026-031
2026-044
2026-052
2026-060
2026-071
2026-080
2026-092

Severity

How the 633 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical6210%
  • High28345%
  • Medium26742%
  • Low203%

Latest CVEs

The 15 most recently published vulnerabilities affecting Opensuse Tumbleweed.

  1. CVE-2026-44950fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow in libXfont29.0
  2. CVE-2026-59679fs_read_glyphs() heap OOB read/write via encoding array index mismatch in libXfont29.0
  3. CVE-2026-59674LPE from suricata user to root due to chown in %post in suricata packaging—
  4. CVE-2026-43502net/rds: handle zerocopy send cleanup before the message is queued7.8
  5. CVE-2026-41051csync2 uses insecure temporary directories when compiled with C99 or later5.0
  6. CVE-2026-3832Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via crafted ocsp response3.7
  7. CVE-2026-3833Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison6.5
  8. CVE-2026-22008Vulnerability in Oracle Java SE (component: Libraries). The supported version that is affected is Oracle Java SE: 25.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with n...3.7
  9. CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
  10. CVE-2026-33636LIBPNG has ARM NEON Palette Expansion Out-of-Bounds Read on AArch647.6
  11. CVE-2025-22873Improper access to parent directory of root in os3.8
  12. CVE-2025-11065Github.com/go-viper/mapstructure/v2: go-viper's mapstructure may leak sensitive information in logs in github.com/go-viper/mapstructure5.3
  13. CVE-2025-43904In SchedMD Slurm before 24.11.5, 24.05.8, and 23.11.11, the accounting system can allow a Coordinator to promote a user to Administrator.4.2
  14. CVE-2026-0892Memory safety bugs fixed in Firefox 147 and Thunderbird 1479.8
  15. CVE-2026-0891Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 1478.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store