Upstream information
Description
Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes - USPS Edition small-package-quotes-usps-edition allows Object Injection.This issue affects Small Package Quotes - USPS Edition: from n/a through <= 1.3.9.Upstream Security Advisories:
- https://www.samba.org/samba/security/CVE-2026-58216.html
- https://www.samba.org/samba/security/CVE-2026-58218.html
- https://www.samba.org/samba/security/CVE-2026-58221.html
- https://www.samba.org/samba/security/CVE-2026-58222.html
- https://www.samba.org/samba/security/CVE-2026-58224.html
- https://www.samba.org/samba/security/CVE-2026-6949.html
SUSE information
Overall state of this security issue: Does not affect SUSE products
This issue is currently rated as having important severity.
| CVSS detail | CNA (audit@patchstack.com) |
|---|---|
| Base Score | 7.2 |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | High |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
| CVSSv3 Version | 3.1 |
SUSE Timeline for this CVE
CVE page created: Fri Jul 17 20:26:12 2026CVE page last modified: Wed Jul 29 11:26:16 2026