Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88763— Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service

Quick assessment

Affected
Red Hat Red Hat Service Interconnect 2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Red Hat Service Interconnect 中的 skupper-router 组件存在一个缺陷,该组件用于在分布式服务之间提供安全的通信。当路由器处理一条经过特殊构造的网络消息并调用其 AMQP 字段解析器时,会触发此问题。由于解析过程中的递归缺少深度限制,路由器可能会耗尽栈内存并崩溃,从而导致整个互联网络出现服务中断(DoS)。

CVSS 5.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88763

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的递归
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Service Interconnect 2 - cpe:/a:redhat:service_interconnect:2

II. Public POCs for CVE-2026-88763

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88763

登录查看更多情报信息。

Vendor Advisories for CVE-2026-88763 (1)

Other References for CVE-2026-88763 (1)

Same Patch Batch · Red Hat · 2026-09-10 · 5 CVEs total

CVE-2026-84042 7.8 HIGH Crun: crun: rootful krun with passt executes container payload as host root
CVE-2026-88770 6.5 MEDIUM Keycloak-services: keycloak-services: device authorization grant issues tokens to brute-fo
CVE-2026-88265 5.6 MEDIUM Crun: crun: /dev/null symlink follow during stdio reopen allows host bind-mount write and
CVE-2026-88264 5.6 MEDIUM Crun: crun: /dev/console symlink follow allows root-owned file creation outside the rootfs

IV. Related Vulnerabilities

V. Comments for CVE-2026-88763

No comments yet


Leave a comment