A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 10 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure communication between distributed services. The issue occurs when the router processes a specially crafted network message using its AMQP field parser. Due to a lack of bounds on recursion during parsing, the router can run out of stack memory and crash, leading to a denial of service for the interconnected network.
Title Skupper-router: skupper-router: unbounded recursion in amqp field parser leads to denial of service
First Time appeared Redhat
Redhat service Interconnect
Weaknesses CWE-674
CPEs cpe:/a:redhat:service_interconnect:2
Vendors & Products Redhat
Redhat service Interconnect
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-10T07:09:10.227Z

Reserved: 2026-09-10T06:55:26.368Z

Link: CVE-2026-88763

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T08:17:02.223

Modified: 2026-09-10T14:50:07.813

Link: CVE-2026-88763

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-10T06:56:33Z

Links: CVE-2026-88763 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T08:30:06Z

Weaknesses