cbcvebase.
CVE-2026-78662
published 2026-09-02

CVE-2026-78662: Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests…

PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.32%
24.5th percentile
Previously, a channel registered in the mux's chanList is not usable until it is established. A malicious peer was able flood the channel's incomingRequests, deadlocking the entire connection. Now, we add an atomic established state, set when a channel becomes usable. Until such a time, handlePacket drops every packet other than the open confirmation/failure, without blocking and without tearing down the connection.

Affected

216 ranges· showing 25
VendorProductVersion rangeFixed in
advanced-cluster-securityrhacs-main-rhel8——
advanced-cluster-securityrhacs-main-rhel9——
advanced-cluster-securityrhacs-operator-bundle——
advanced-cluster-securityrhacs-rhel8-operator——
advanced-cluster-securityrhacs-rhel9-operator——
advanced-cluster-securityrhacs-roxctl-rhel8——
advanced-cluster-securityrhacs-roxctl-rhel9——
advanced-cluster-securityrhacs-scanner-rhel8——
advanced-cluster-securityrhacs-scanner-rhel9——
advanced-cluster-securityrhacs-scanner-slim-rhel8——
advanced-cluster-securityrhacs-scanner-slim-rhel9——
advanced-cluster-securityrhacs-scanner-v4-rhel8——
advanced-cluster-securityrhacs-scanner-v4-rhel9——
assistedagent-preinstall-image-builder-rhel9——
buildah_projectbuildah——
cert-managerjetstack-cert-manager-acmesolver-rhel9——
cert-managerjetstack-cert-manager-rhel9——
complianceopenshift-security-profiles-operator-bundle——
complianceopenshift-security-profiles-rhel8-operator——
container-native-virtualizationcluster-network-addons-operator——
container-native-virtualizationcluster-network-addons-operator-rhel9——
container-tools_rhel8buildah——
container-tools_rhel8podman——
cryostatcryostat-storage-rhel9——
devspacestraefik-rhel9——

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.