REDHAT-BUG-2531301: Medium severity Red Hat skupper-router vulnerability

Published Sep 10, 2026
·
Updated

A denial-of-service vulnerability was discovered in skupper-router within the AMQP field parser. The flaw is caused by unbounded recursion when processing deeply nested or specially crafted AMQP messages, leading to a stack overflow. An attacker who can send messages to the router can trigger this crash. Exploitation requires the attacker to possess a valid x.509 certificate signed by the Red Hat Service Interconnect network's certificate authority. Successful exploitation results in the skupper-router process crashing, terminating all active connections and preventing new traffic from being routed through the affected node.

Affected Software

1 affected component
Red Hat skupper-router

Event History

Sep 10, 2026
Data Sourced
via Red Hat·06:55 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must be able to send AMQP messages to the router and possess a valid X.509 certificate signed by the Red Hat Service Interconnect network certificate authority.

2

What is the operational impact of successful exploitation?

Successful exploitation crashes the skupper-router process. This terminates active connections and prevents the affected node from routing new traffic.

3

What type of input triggers the crash?

The issue is triggered by deeply nested or specially crafted AMQP messages that cause unbounded recursion in the AMQP field parser, resulting in a stack overflow.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203