<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:cockpit-Project:cockpit:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3acockpit-projectcockpit/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 18:08:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3acockpit-projectcockpit/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-91149: Denial of Service via Resource Exhaustion in Cockpit</title><link>https://feed.craftedsignal.io/briefs/2026-09-cockpit-dos/</link><pubDate>Fri, 18 Sep 2026 18:08:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cockpit-dos/</guid><description>An unauthenticated remote attacker can exploit CVE-2026-91149 in Cockpit by exhausting system resources through numerous simultaneous connections to the cockpit-tls service.</description><content:encoded><![CDATA[<p>A vulnerability identified as CVE-2026-91149 exists in the Cockpit server management software, specifically within the cockpit-tls component. The flaw allows an unauthenticated, remote attacker to trigger a denial of service (DoS) condition. By initiating and sustaining a large volume of simultaneous connections to the cockpit-tls service, an attacker forces the application to spawn an unbounded number of detached threads. This process consumes excessive system resources, including memory and file descriptors, which eventually leads to the degradation or complete unavailability of the Cockpit service for legitimate users. Defenders should monitor for anomalous connection patterns directed at the Cockpit TLS port and evaluate infrastructure resilience against resource exhaustion attacks.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the unavailability of the Cockpit interface, impacting system administrators' ability to perform server management tasks. While the attack is limited to a service-level denial of service, the widespread use of Cockpit across enterprise Linux environments makes this a significant availability risk.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize monitoring of the cockpit-tls service for abnormal connection counts and duration. Work with IT operations to ensure system resource limits are configured to mitigate the impact of thread-exhaustion events on the host OS.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>denial-of-service</category><category>vulnerability</category></item></channel></rss>