Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-91149

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 18, 2026
Vendor unknown

Description

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users.

References