Medium severity5.9NVD Advisory· Published Sep 18, 2026
CVE-2026-91147
CVE-2026-91147
Description
A flaw was found in cockpit-ws. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the WebService.UrlRoot is configured and a request is made to the exact URL-root prefix without a trailing slash, cockpit-ws can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.