CVE-2026-96609 Details
Description
Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console loop with no recognized termination condition. This is only exploitable by users who can send console subscription commands to unikernels that produce sufficient log output to fill the ring buffer (1024 lines). It is not exploitable by unauthorized clients.
A memory exhaustion vulnerability has been identified in Robur Albatross versions 1.0.0 through 2.7.1. The issue arises in the albatross-console, which fails to properly manage the ring buffer used for logging console messages from unikernels. This flaw creates an infinite loop with no termination condition, leading to denial-of-service by exhausting available memory. The vulnerability can only be exploited by users who have permission to send console subscription commands to unikernels that generate enough log output to fill the ring buffer, which has a capacity of 1024 lines. Unauthorized clients cannot exploit this vulnerability.
Users can upgrade to Robur Albatross version 2.7.2 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 23, 2026CISA-ADP
Assessed Sep 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/robur-coop/albatross/pull/273 | [email protected] | Issue TrackingVendor |
| https://osv.dev/vulnerability/OSEC-2026-09 | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Robur Albatross | >= 1.0.0, < 2.7.2 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Modified | CISA-ADP |
| Sep 23, 2026 | New CVE Received | [email protected] |
Volerion