Skip to content

CVE 2026 91149

access.redhat.com • September 19, 2026

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the cockpit-tls service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users.

This is an Important denial-of-service flaw in Cockpit, allowing unauthenticated remote attackers to degrade or deny service availability. Exploitation requires network reachability to the Cockpit listener on TCP port 9090, enabling attackers to exhaust system resources by spawning unbounded connection threads. The impact is limited to availability, without affecting confidentiality or integrity.

Bugzilla 2479422 : cockpit: Cockpit: Denial of Service via unbounded connection thread spawning

CWE-770 : Allocation of Resources Without Limits or Throttling

Common Vulnerability Scoring System (CVSS) Score Details

Info alert: Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications ).

The following CVSS metrics and score provided are preliminary and subject to review.

CVSS v3 Score Breakdown

Red Hat: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Understanding the Weakness (CWE)

Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)

When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.

This issue was discovered by AISLE Research and Found by AISLE in partnership with Red Hat.

Frequently Asked Questions

"Under investigation" doesn't necessarily mean that the product is affected by this vulnerability. It only means that our Analysis Team is still working on determining whether the product is affected and how it is affected.

The term 'Affected' means that our Analysis team has determined that this product, such as Red Hat Enterprise Linux 8 or OpenShift Container Platform 4, is affected by this vulnerability and a fix may be released to address this issue in the near future. This includes all minor releases of this product unless noted otherwise in the Statement text.

Upgrade to a supported product version that includes a fix for this vulnerability (recommended).

Apply a mitigation (if one exists).

Customers with the Technical Account Manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.

Apply a mitigation (if one exists).

Red Hat Engineering focuses on addressing high-priority issues based on the impact and product lifecycle expectations. Therefore, lower-priority issues will not receive immediate fixes.

Customers with the technical account manager (TAM) RHEL Security Select Add-on can review this CVE directly with their TAM.

Not sure what something means? Check out our Security Glossary .

For clarification or corrections, please Red Hat Product Security .