← Back to browse · API

CVE-2026-56004

Severity
CRITICAL
CVSS
10.0
EPSS
0.00375
Risk score
40.13
CISA KEV
No
PoC
No
Published
2026-07-02
Modified
2026-07-02
First seen
2026-08-07
Aliases
EUVD-2026-41404, GHSA-F3XH-PCQP-FPCM
Products
opensuse:buildservice 0 <0.12.4
Sources
euvd EUVD-2026-41404

Description

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _service file to execute code as the source service or the local user checking out the malicious services

References