Junglewise Threat Intelligence

CVE-2026-17639: HP Smart Tank All-in-One denial of service via concurrent HTTP requests

CVE-2026-17639 · Severity: info · Published 2026-08-17

Vendors: Hp.

Executive brief

Certain HP Smart Tank All-in-One printers contain a vulnerability allowing unauthenticated attackers to render the device unavailable by sending multiple concurrent HTTP requests. This could disrupt printing operations and user productivity without requiring authentication or special access.

Technical details

The vulnerability is a denial of service condition in certain HP Smart Tank All-in-One printer models. An unauthenticated attacker can exploit this by sending multiple concurrent HTTP requests to the device, causing it to become unavailable or unresponsive. No authentication is required and the attack is network-accessible. The impact is availability-focused, rendering the printer unable to process print jobs or respond to legitimate requests. Patch status is unknown from the provided advisory data.

Affected products

  • HP Smart Tank All-in-One

Timeline

  • 2026-08-17: disclosed

References