What is CVE-2026-76235?
CVE-2026-76235 is a memory leak vulnerability in Cockpit's web service (cockpit-ws). The login page handler leaks a heap allocation on every unauthenticated request containing a CockpitLang cookie, potentially allowing a remote attacker to exhaust host memory and cause a denial of service.
Azərbaycanca: CVE-2026-76235, Cockpit idarəetmə panelində aşkar edilmiş bir memory leak zəifliyidir. Autentifikasiya olunmamış istifadəçilər tərəfindən göndərilən xüsusi CockpitLang cookie-i login səhifəsində heap səviyyəsində yaddaş sızmasına səbəb olur. Bu qüsurdan istifadə edərək uzaqdan hücum edən şəxs serverin yaddaşını tükədərək denial of service (DoS) yarada bilər.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
How is CVE-2026-76235 exploited in the Cockpit management panel?
An attacker can trigger a heap-level memory leak on the login page by sending unauthenticated requests containing a crafted CockpitLang cookie, potentially exhausting the host memory and causing a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.