cve-2026-13503

csaf_opensuse
Description

SUSE CVE-2026-13503

Timeline
Published
2026-06-30 01:49 UTC
Last Modified
2026-06-30
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "SUSE CVE-2026-13503",
        "title": "Title"
      },
      {
        "category": "description",
        "text": "A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
        "title": "Description of the CVE"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "CVE-2026-13503",
        "url": "https://www.suse.com/security/cve/CVE-2026-13503"
      },
      {
        "category": "external",
        "summary": "SUSE Security Ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "external",
        "summary": "SUSE Bug 1269487 for CVE-2026-13503",
        "url": "https://bugzilla.suse.com/1269487"
      }
    ],
    "title": "SUSE CVE CVE-2026-13503",
    "tracking": {
      "current_release_date": "2026-06-30T01:49:34Z",
      "generator": {
        "date": "2026-06-30T01:49:34Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf-vex.pl",
          "version": "1"
        }
      },
      "id": "CVE-2026-13503",
      "initial_release_date": "2026-06-30T01:49:34Z",
      "revision_history": [
        {
          "date": "2026-06-30T01:49:34Z",
          "number": "2",
          "summary": "vulnerabilities added,references added,severity changed from  to moderate"
        }
      ],
      "status": "interim",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
                "product": {
                  "name": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
                  "product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:packagehub:15:sp7"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "antlr4",
                "product": {
                  "name": "antlr4",
                  "product_id": "antlr4",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/antlr4@"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libantlr4-runtime-devel",
                "product": {
                  "name": "libantlr4-runtime-devel",
                  "product_id": "libantlr4-runtime-devel",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/libantlr4-runtime-devel@?upstream=antlr4.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libantlr4-runtime4_7_2",
                "product": {
                  "name": "libantlr4-runtime4_7_2",
                  "product_id": "libantlr4-runtime4_7_2",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/libantlr4-runtime4_7_2@?upstream=antlr4.src.rpm"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libantlr4-runtime-devel as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
          "product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime-devel"
        },
        "product_reference": "libantlr4-runtime-devel",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libantlr4-runtime4_7_2 as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
          "product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime4_7_2"
        },
        "product_reference": "libantlr4-runtime4_7_2",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "antlr4 as component of SUSE Linux Enterprise Module for Package Hub 15 SP7",
          "product_id": "SUSE Linux Enterprise Module for Package Hub 15 SP7:antlr4"
        },
        "product_reference": "antlr4",
        "relates_to_product_reference": "SUSE Linux Enterprise Module for Package Hub 15 SP7"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-13503",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-13503"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "known_affected": [
          "SUSE Linux Enterprise Module for Package Hub 15 SP7:antlr4",
          "SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime-devel",
          "SUSE Linux Enterprise Module for Package Hub 15 SP7:libantlr4-runtime4_7_2"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-13503",
          "url": "https://www.suse.com/security/cve/CVE-2026-13503"
        },
        {
          "category": "external",
          "summary": "SUSE Security Ratings",
          "url": "https://www.suse.com/support/security/rating/"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1269487 for CVE-2026-13503",
          "url": "https://bugzilla.suse.com/1269487"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-06-28T18:00:06Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-13503"
    }
  ]
}
Enrichment data
View JSON API Download JSON