Junglewise Threat Intelligence

CVE-2026-88763: Red Hat Service Interconnect skupper-router unbounded recursion denial of service

CVE-2026-88763 · Severity: medium · CVSS 5.9 · Published 2026-09-10

Vendors: Red Hat.

Executive brief

Red Hat Service Interconnect uses the skupper-router component to enable secure communication between distributed services across networks. An attacker with a valid certificate can send a specially crafted network message that causes the router to crash due to excessive recursion, disrupting the interconnected network and causing service outages for dependent applications.

Technical details

The vulnerability is an uncontrolled recursion flaw (CWE-674) in the AMQP field parser within the skupper-router component. When processing a specially crafted network message, the parser lacks bounds on recursion depth, causing it to exhaust stack memory and crash. The attack requires network access and a valid x.509 certificate signed by the internal network's certificate authority, but requires no user interaction. Successful exploitation results in denial of service by crashing the router process. Patches are expected from Red Hat for affected versions.

Affected products

  • Red Hat Service Interconnect <UNKNOWN>

Timeline

  • 2026-09-10: disclosed
  • 2026-09-10: advisory

References