{"id":"UBUNTU-CVE-2026-91147","details":"A flaw was found in `cockpit-ws`. This vulnerability allows a remote, unauthenticated attacker to cause a Denial of Service (DoS) by sending a specially crafted request. When the `WebService.UrlRoot` is configured and a request is made to the exact URL-root prefix without a trailing slash, `cockpit-ws` can terminate unexpectedly. This issue leads to the unavailability of the Cockpit web service.","modified":"2026-09-21T21:38:11.481752560Z","published":"2026-09-21T00:00:00Z","upstream":["CVE-2026-91147"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-91147"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-91147"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2479230"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-91147"}],"affected":[{"package":{"name":"cockpit","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/cockpit?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["151-1","156-1","157-1","158-1","160-1","161-1","162-1","163-1","164-1"],"ecosystem_specific":{"binaries":[{"binary_name":"cockpit","binary_version":"164-1"},{"binary_version":"164-1","binary_name":"cockpit-bridge"},{"binary_name":"cockpit-dashboard","binary_version":"164-1"},{"binary_version":"164-1","binary_name":"cockpit-docker"},{"binary_version":"164-1","binary_name":"cockpit-machines"},{"binary_version":"164-1","binary_name":"cockpit-networkmanager"},{"binary_name":"cockpit-packagekit","binary_version":"164-1"},{"binary_version":"164-1","binary_name":"cockpit-storaged"},{"binary_name":"cockpit-system","binary_version":"164-1"},{"binary_name":"cockpit-tests","binary_version":"164-1"},{"binary_name":"cockpit-ws","binary_version":"164-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91147.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/cockpit?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["202.1-1","204-1","206-1","207-1","208-1","210-1","211-1","212-1","213-1","214.1-1","215-1"],"ecosystem_specific":{"binaries":[{"binary_name":"cockpit","binary_version":"215-1"},{"binary_version":"215-1","binary_name":"cockpit-bridge"},{"binary_name":"cockpit-dashboard","binary_version":"215-1"},{"binary_version":"215-1","binary_name":"cockpit-machines"},{"binary_name":"cockpit-networkmanager","binary_version":"215-1"},{"binary_version":"215-1","binary_name":"cockpit-packagekit"},{"binary_version":"215-1","binary_name":"cockpit-pcp"},{"binary_name":"cockpit-storaged","binary_version":"215-1"},{"binary_name":"cockpit-system","binary_version":"215-1"},{"binary_name":"cockpit-tests","binary_version":"215-1"},{"binary_name":"cockpit-ws","binary_version":"215-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91147.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/cockpit?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["252-1","256-1","257-1","258-1","259-1","260-1","261-1","262-1","263-1","264-1","264-1ubuntu0.22.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"cockpit","binary_version":"264-1ubuntu0.22.04.1"},{"binary_name":"cockpit-bridge","binary_version":"264-1ubuntu0.22.04.1"},{"binary_name":"cockpit-networkmanager","binary_version":"264-1ubuntu0.22.04.1"},{"binary_name":"cockpit-packagekit","binary_version":"264-1ubuntu0.22.04.1"},{"binary_name":"cockpit-pcp","binary_version":"264-1ubuntu0.22.04.1"},{"binary_version":"264-1ubuntu0.22.04.1","binary_name":"cockpit-sosreport"},{"binary_name":"cockpit-storaged","binary_version":"264-1ubuntu0.22.04.1"},{"binary_version":"264-1ubuntu0.22.04.1","binary_name":"cockpit-system"},{"binary_version":"264-1ubuntu0.22.04.1","binary_name":"cockpit-tests"},{"binary_name":"cockpit-ws","binary_version":"264-1ubuntu0.22.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91147.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/cockpit?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["300.1-1","303-1","304-1","305-1","306-1","307-1","308-1","309-1","310.1-1","311-1","312-1build2","314-1"],"ecosystem_specific":{"binaries":[{"binary_name":"cockpit","binary_version":"314-1"},{"binary_name":"cockpit-bridge","binary_version":"314-1"},{"binary_version":"314-1","binary_name":"cockpit-networkmanager"},{"binary_version":"314-1","binary_name":"cockpit-packagekit"},{"binary_version":"314-1","binary_name":"cockpit-pcp"},{"binary_name":"cockpit-sosreport","binary_version":"314-1"},{"binary_name":"cockpit-storaged","binary_version":"314-1"},{"binary_version":"314-1","binary_name":"cockpit-system"},{"binary_name":"cockpit-tests","binary_version":"314-1"},{"binary_name":"cockpit-ws","binary_version":"314-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91147.json"}},{"package":{"name":"cockpit","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/cockpit?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["346-1","348-1","350-1","352-1","353.1-1","354-1","355-1","356-1","360-1"],"ecosystem_specific":{"binaries":[{"binary_name":"cockpit","binary_version":"360-1"},{"binary_name":"cockpit-bridge","binary_version":"360-1"},{"binary_version":"360-1","binary_name":"cockpit-networkmanager"},{"binary_name":"cockpit-packagekit","binary_version":"360-1"},{"binary_version":"360-1","binary_name":"cockpit-sosreport"},{"binary_name":"cockpit-storaged","binary_version":"360-1"},{"binary_version":"360-1","binary_name":"cockpit-system"},{"binary_version":"360-1","binary_name":"cockpit-ws"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-91147.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}