CVE-2026-96609

Source
https://cve.org/CVERecord?id=CVE-2026-96609
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96609.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-96609
Aliases
Published
2026-09-23T14:07:16Z
Modified
2026-09-25T03:48:28Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients.

Database specific
{
    "cna_assigner":  "mitre",
    "cwe_ids":  [
        "CWE-770"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/96xxx/CVE-2026-96609.json"
}
References

Affected packages

Git / github.com/robur-coop/albatross

Affected ranges

Type
GIT
Repo
https://github.com/robur-coop/albatross
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.0.0"
        },
        {
            "fixed":  "2.7.2"
        },
        {
            "introduced":  "0"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v1.*
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.2.0
v1.3.0
v1.3.1
v1.4.0
v1.4.1
v1.4.2
v1.4.3
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.5.4
v1.5.5
v1.5.6
v2.*
v2.0.0
v2.1.0
v2.2.0
v2.3.0
v2.4.0
v2.4.1
v2.5.0
v2.5.1
v2.6.0
v2.6.1
v2.7.0
v2.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-96609.json"