cve-2026-13503
csaf_opensuse
Description
SUSE CVE-2026-13503
Timeline
- Published
- 2026-06-30 01:49 UTC
- Last Modified
- 2026-06-30
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"document": {
"aggregate_severity": {
"namespace": "https://www.suse.com/support/security/rating/",
"text": "moderate"
},
"category": "csaf_vex",
"csaf_version": "2.0",
"distribution": {
"text": "Copyright 2024 SUSE LLC. All rights reserved.",
"tlp": {
"label": "WHITE",
"url": "https://www.first.org/tlp/"
}
},
"lang": "en",
"notes": [
{
"category": "summary",
"text": "SUSE CVE-2026-13503",
"title": "Title"
},
{
"category": "description",
"text": "A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"title": "Description of the CVE"
},
{
"category": "legal_disclaimer",
"text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
"title": "Terms of use"
}
],
"publisher": {
"category": "vendor",
"contact_details": "https://www.suse.com/support/security/contact/",
"name": "SUSE Product Security Team",
"namespace": "https://www.suse.com/"
},
"references": [
{
"category": "external",
"summary": "CVE-2026-13503",
"url": "https://www.suse.com/security/cve/CVE-2026-13503"
},
{
"category": "external",
"summary": "SUSE Security Ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "external",
"summary": "SUSE Bug 1269487 for CVE-2026-13503",
"url": "https://bugzilla.suse.com/1269487"
}
],
"title": "SUSE CVE CVE-2026-13503",
"tracking": {
"current_release_date": "2026-06-30T01:49:34Z",
"generator": {
"date": "2026-06-30T01:49:34Z",
"engine": {
"name": "cve-database.git:bin/generate-csaf-vex.pl",
"version": "1"
}
},
"id": "CVE-2026-13503",
"initial_release_date": "2026-06-30T01:49:34Z",
"revision_history": [
{
"date": "2026-06-30T01:49:34Z",
"number": "2",
"summary": "vulnerabilities added,references added,severity changed from to moderate"
}
],
"status": "interim",
"version": "2"
}
},
"product_tree": {
"branches": [
{
"branches": [
{
"branches": [
{
"category": "product_name",
"name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product": {
"name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_identification_helper": {
"cpe": "cpe:/o:suse:packagehub:15:sp7"
}
}
},
{
"category": "product_version",
"name": "antlr4",
"product": {
"name": "antlr4",
"product_id": "antlr4",
"product_identification_helper": {
"purl": "pkg:rpm/suse/antlr4@"
}
}
},
{
"category": "product_version",
"name": "libantlr4-runtime-devel",
"product": {
"name": "libantlr4-runtime-devel",
"product_id": "libantlr4-runtime-devel",
"product_identification_helper": {
"purl": "pkg:rpm/suse/libantlr4-runtime-devel@?upstream=antlr4.src.rpm"
}
}
},
{
"category": "product_version",
"name": "libantlr4-runtime4_7_2",
"product": {
"name": "libantlr4-runtime4_7_2",
"product_id": "libantlr4-runtime4_7_2",
"product_identification_helper": {
"purl": "pkg:rpm/suse/libantlr4-runtime4_7_2@?upstream=antlr4.src.rpm"
}
}
}
],
"category": "product_family",
"name": "SUSE Linux Enterprise"
}
],
"category": "vendor",
"name": "SUSE"
}
],
"relationships": [
{
"category": "default_component_of",
"full_product_name": {
"name": "libantlr4-runtime-devel as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime-devel"
},
"product_reference": "libantlr4-runtime-devel",
"relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "libantlr4-runtime4_7_2 as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime4_7_2"
},
"product_reference": "libantlr4-runtime4_7_2",
"relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
},
{
"category": "default_component_of",
"full_product_name": {
"name": "antlr4 as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
"product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:antlr4"
},
"product_reference": "antlr4",
"relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
}
]
},
"vulnerabilities": [
{
"cve": "CVE-2026-13503",
"ids": [
{
"system_name": "SUSE CVE Page",
"text": "https://www.suse.com/security/cve/CVE-2026-13503"
}
],
"notes": [
{
"category": "general",
"text": "A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
"title": "CVE description"
}
],
"product_status": {
"known_affected": [
"SUSE Linux Enterprise Module for Package Hub 15 SP7:antlr4",
"SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime-devel",
"SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime4_7_2"
]
},
"references": [
{
"category": "external",
"summary": "CVE-2026-13503",
"url": "https://www.suse.com/security/cve/CVE-2026-13503"
},
{
"category": "external",
"summary": "SUSE Security Ratings",
"url": "https://www.suse.com/support/security/rating/"
},
{
"category": "external",
"summary": "SUSE Bug 1269487 for CVE-2026-13503",
"url": "https://bugzilla.suse.com/1269487"
}
],
"threats": [
{
"category": "impact",
"date": "2026-06-28T18:00:06Z",
"details": "moderate"
}
],
"title": "CVE-2026-13503"
}
]
}
Enrichment data
Aggregated bundle (all enrichments)