Hi, The following vulnerability was published for cups. CVE-2026-105326[0]: | An argument injection flaw was found in CUPS. When email | notification is configured, the CUPS scheduler accepts printer | subscription requests that supply a mailto notify-recipient-uri. The | mailto notifier passes the recipient address to the configured | sendmail program without ensuring it cannot be interpreted as | command-line options. A remote attacker who can reach the CUPS | service could supply a crafted recipient value starting with "-" to | influence sendmail behavior. Successful exploitation depends on the | installed mail transfer agent and CUPS network exposure, and may | lead to execution of attacker-controlled commands with the | privileges of the CUPS service user. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-105326 https://www.cve.org/CVERecord?id=CVE-2026-105326 [1] https://github.com/OpenPrinting/cups/security/advisories/GHSA-r4wf-366f-f6g3 [2] https://github.com/OpenPrinting/cups/commit/611d1bd3bdf832363832383567906a6d7fd6c47d Please adjust the affected versions in the BTS as needed. Regards, Salvatore