Description
A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 18 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service. | |
| Title | Cockpit: cockpit: denial of service in `cockpit-ws` due to url-root handling without a trailing slash | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat openshift Devspaces |
|
| Weaknesses | CWE-617 | |
| CPEs | cpe:/a:redhat:openshift_devspaces:3 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat openshift Devspaces |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T16:43:51.546Z
Reserved: 2026-09-14T20:35:52.198Z
Link: CVE-2026-91147
No data.
Status : Awaiting Analysis
Published: 2026-09-18T17:17:05.427
Modified: 2026-09-18T19:06:08.407
Link: CVE-2026-91147
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-617
Reachable Assertion