Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76235

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.

Отчет

Red Hat rates this issue as Moderate impact. Although cockpit-ws is reachable by an unauthenticated remote client and the resulting memory exhaustion can be sustained indefinitely, cockpit-ws is a stateless web console component: its crash or restart does not itself compromise the confidentiality or integrity of the host or of other running services, and the process is automatically restarted by systemd.

Меры по смягчению последствий

Restrict network access to the cockpit port to trusted clients until a fix is available. No configuration-level mitigation removes the flaw entirely, since the login page must remain reachable without authentication.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cockpitAffected
Red Hat Enterprise Linux 7cockpitAffected
Red Hat Enterprise Linux 8cockpitAffected
Red Hat Enterprise Linux 9cockpitAffected
Red Hat OpenShift Dev Spacesdevspaces/udi-base-rhel10Not affected
Red Hat OpenShift Dev Spacesdevspaces/udi-base-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/udi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2519497cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via CockpitLang cookie in send_login_html

EPSS

Процентиль: 28%
0.00355
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

(A memory leak flaw was found in cockpit-ws. The login page handler lea ...)

CVSS3: 7.5
nvd
8 дней назад

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.

CVSS3: 7.5
debian
8 дней назад

A memory leak flaw was found in cockpit-ws. The login page handler lea ...

CVSS3: 7.5
github
8 дней назад

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.

EPSS

Процентиль: 28%
0.00355
Низкий

7.5 High

CVSS3

Уязвимость CVE-2026-76235