PT-2026-97337 · Robur · Robur Albatross

CVE-2026-96609

·

Published

2026-05-28

·

Updated

2026-09-23

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Robur Albatross versions 1.0.0 through 2.7.1
Description A flaw in the ring buffer logic of albatross-console allows a user to trigger an infinite loop when the buffer is full (1024 lines), leading to denial of service and memory exhaustion. This occurs when a client sends a specially crafted query for console logs via the unix domain socket or the albatross-tls-endpoint. The issue is triggered if a timestamp earlier than all recorded output is used, or if a very large or negative count is provided, causing the system to accumulate entries indefinitely. This is only exploitable by users authorized to send console subscription commands to unikernels that produce enough log output to fill the ring buffer.
Recommendations Update Robur Albatross to version 2.7.2 or later.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96609
OSEC-2026-09

Affected Products

Robur Albatross