Impact
A flaw in the skupper-router component of Red Hat Service Interconnect 2 causes unbounded recursion during AMQP field parsing. When the router processes a specially crafted AMQP message, the recursive parser can exhaust stack memory and crash, resulting in a denial of service for the interconnected services. This is a stack overflow condition described by CWE-674.
Affected Systems
The vulnerability affects the skupper-router component of Red Hat Service Interconnect version 2. No specific sub‑versions are listed, so any installation of the 2.x release that uses skupper-router is potentially affected.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the EPSS score is not available. The issue is not listed in CISA KEV catalog. The likely attack vector is a malicious AMQP message sent over the network from an external or untrusted source, which can trigger the recursion and crash the router.
OpenCVE Enrichment