CVE-2026-91147

Summary

A flaw was found in cockpit-ws. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the WebService.UrlRoot is configured and a request is made to the exact URL-root prefix without a trailing slash, cockpit-ws can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.

Affected Software

VendorProductVersion RangeStatus

Weaknesses

  • CWE-617: Reachable Assertion

References