Description
A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Published: 2026-09-10
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A flaw in the skupper-router component of Red Hat Service Interconnect 2 causes unbounded recursion during AMQP field parsing. When the router processes a specially crafted AMQP message, the recursive parser can exhaust stack memory and crash, resulting in a denial of service for the interconnected services. This is a stack overflow condition described by CWE-674.

Affected Systems

The vulnerability affects the skupper-router component of Red Hat Service Interconnect version 2. No specific sub‑versions are listed, so any installation of the 2.x release that uses skupper-router is potentially affected.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available. The issue is not listed in CISA KEV catalog. The likely attack vector is a malicious AMQP message sent over the network from an external or untrusted source, which can trigger the recursion and crash the router.

Generated by OpenCVE AI on September 10, 2026 at 08:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade skupper-router to the latest Red Hat Service Interconnect release containing the recursive bounds check patch.
  • Restrict inbound traffic to the router using firewall rules or network segmentation, allowing only trusted hosts to send AMQP messages.
  • Enable monitoring and logging of the skupper-router process to detect crashes and configure automatic restarts to maintain service availability.

Generated by OpenCVE AI on September 10, 2026 at 08:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Title Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service
First Time appeared Redhat
Redhat service Interconnect
Weaknesses CWE-674
CPEs cpe:/a:redhat:service_interconnect:2
Vendors & Products Redhat
Redhat service Interconnect
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Service Interconnect
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-10T07:09:10.227Z

Reserved: 2026-09-10T06:55:26.368Z

Link: CVE-2026-88763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T08:17:02.223

Modified: 2026-09-10T08:17:02.223

Link: CVE-2026-88763

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T08:30:06Z

Weaknesses