Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88763

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 5.9

Описание

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.

Отчет

The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that exploitation requires the attacker to have a valid x.509 certificate signed by the internal network's certificate authority. Successful exploitation allows an attacker to crash the skupper-router process, leading to a denial of service. The vulnerability's root cause is a lack of recursion depth limits in the AMQP field parsing logic.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Service Interconnect 2skupper-routerAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-674
https://bugzilla.redhat.com/show_bug.cgi?id=2531301skupper-router: skupper-router: Unbounded recursion in AMQP field parser leads to denial of service

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
6 дней назад

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.

CVSS3: 5.9
github
6 дней назад

A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.

5.9 Medium

CVSS3