{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3acockpit-projectcockpit/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:cockpit-project:cockpit:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-91149"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["cockpit"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Cockpit Project"],"content_html":"\u003cp\u003eA vulnerability identified as CVE-2026-91149 exists in the Cockpit server management software, specifically within the cockpit-tls component. The flaw allows an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. By initiating and sustaining a large volume of simultaneous connections to the cockpit-tls service, an attacker forces the application to spawn an unbounded number of detached threads. This process consumes excessive system resources, including memory and file descriptors, which eventually leads to the degradation or complete unavailability of the Cockpit service for legitimate users. Defenders should monitor for anomalous connection patterns directed at the Cockpit TLS port and evaluate infrastructure resilience against resource exhaustion attacks.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unavailability of the Cockpit interface, impacting system administrators' ability to perform server management tasks. While the attack is limited to a service-level denial of service, the widespread use of Cockpit across enterprise Linux environments makes this a significant availability risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize monitoring of the cockpit-tls service for abnormal connection counts and duration. Work with IT operations to ensure system resource limits are configured to mitigate the impact of thread-exhaustion events on the host OS.\u003c/p\u003e\n","date_modified":"2026-09-18T18:08:49Z","date_published":"2026-09-18T18:08:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cockpit-dos/","summary":"An unauthenticated remote attacker can exploit CVE-2026-91149 in Cockpit by exhausting system resources through numerous simultaneous connections to the cockpit-tls service.","title":"CVE-2026-91149: Denial of Service via Resource Exhaustion in Cockpit","url":"https://feed.craftedsignal.io/briefs/2026-09-cockpit-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:cockpit-Project:cockpit:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}