{"id":"CVE-2026-88763","title":"A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services","summary":"A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message …","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-674"],"vendor":"Red Hat","product":"skupper-router","affected":["skupper-router (all versions)"],"published":"2026-09-10","updated":"2026-09-14","sourceUpdated":"2026-09-14T17:17:53.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-88763","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-88763","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2531301","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T16:36:19.640574Z"},"epss":0.0025,"epssPercentile":0.16626,"ingestedAt":"2026-09-12T17:18:26.950Z","slug":"CVE-2026-88763","body":"## Overview\n\nA flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}