CVE-2026-91147Medium· 5.9▾ SunlitA flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made t…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
A flaw was found in cockpit-ws. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the WebService.UrlRoot is configured and a request is made to the exact URL-root prefix without a trailing slash, cockpit-ws can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91149High· 7.5A flaw was found in Cockpit
CVE-2026-91142Low· 3.6A flaw was found in Cockpit
CVE-2026-89716Medium· 4.4kernel: Linux kernel zram: Denial of Service due to improper deflate parameter validation (CVE-2026-89716)
CVE-2026-89727High· 7.0kernel: KVM: arm64: GICv2: Don't WARN on out-of-range GICV_DIR INTID (CVE-2026-89727)
CVE-2026-27135High· 7.5nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135)
CVE-2026-45819High· 7.5baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service.