CVE-2026-105217

Source
https://cve.org/CVERecord?id=CVE-2026-105217
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105217.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105217
Published
2026-10-04T17:09:52Z
Modified
2026-10-06T02:47:20Z
Severity
  • 2.3 (Low) CVSS_V4 - CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php
Details

Cockpit CMS 2.12.0 before 2.14.1 disables TLS certificate verification in the cron.php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-295"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105217.json"
}
References

Affected packages

Git / github.com/cockpit-hq/cockpit

Affected ranges

Type
GIT
Repo
https://github.com/cockpit-hq/cockpit
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.12.0"
        },
        {
            "fixed":  "2.14.1"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

2.*
2.12.0
2.12.1
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
2.13.5
2.14.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105217.json"