---
id: CVE-2026-96609
title: >-
  Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring
  buffer, leading to an albatross-console loop with no recognized termination
  condition
summary: >-
  Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring
  buffer, leading to an albatross-console loop with no recognized termination
  condition. This is only exploitable by users who can send console subscription
  comm…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-770
vendor: Robur
product: Albatross
affected:
  - Albatross >= 1.0.0 < 2.7.2
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96609'
references:
  - url: 'https://github.com/robur-coop/albatross/pull/273'
    label: cve@mitre.org
  - url: 'https://osv.dev/vulnerability/OSEC-2026-09'
    label: cve@mitre.org
tags:
  - nvd
  - cve.org
epss: 0.00235
epssPercentile: 0.12848
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T15:21:49.993447Z'
cvssSource: cna
ingestedAt: '2026-09-23T14:25:29.808Z'
---

## Overview

Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
