cockpit-ws是Cockpit组织的一款用于浏览器应用程序与各种配置工具和服务(如cockpit-bridge (8))之间通信的 Web 服务组件 。 cockpit-ws存在资源管理错误漏洞,该漏洞源于登录页面处理器在处理携带CockpitLang cookie的未认证请求时泄漏堆分配,可能导致远程未认证攻击者耗尽主机内存并导致拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 7 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 8 | any |
affected |
| Red Hat | Red Hat Enterprise Linux 9 | any |
affected |
| Red Hat | Red Hat OpenShift Dev Spaces | any |
unaffected |
any |
unaffected | ||
any |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| Red Hat | Red Hat OpenShift Dev Spaces | - |
cpe:/a:redhat:openshift_devspaces:3
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-70496 | 9.9 CRITICAL | Search-v2-operator: search-v2-operator: operator clusterrole is cluster-admin equivalent v |
| CVE-2026-66794 | 9.3 CRITICAL | Cluster-proxy-addon: cluster-proxy-addon: unauthenticated ssrf to arbitrary managed-cluste |
| CVE-2026-71470 | 9.1 CRITICAL | Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow uns |
| CVE-2026-76139 | 8.0 HIGH | Acm-operator-bundle: acm-operator-bundle: bundle build execs unpinned stolostron/release@m |
| CVE-2026-75569 | 7.7 HIGH | Mce-operator-bundle: mce-operator-bundle: bundle-generation business logic fetched from mu |
| CVE-2026-76827 | 6.8 MEDIUM | Search-indexer: search-indexer: update/delete operations not scoped to caller's cluster (c |
| CVE-2026-18874 | 6.2 MEDIUM | Volsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml v |
| CVE-2026-75900 | 6.1 MEDIUM | Swtpm: swtpm: out-of-bounds read in swtpm_nvram_checkheader due to sizeof(pointer) vs size |
| CVE-2026-76166 | 4.3 MEDIUM | Modcluster-core: mod_cluster advertise listener: unauthenticated dos via crafted multicast |
No comments yet