CVE-2026-22904Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overflow, resulting in a denial‑of‑service condition and possible remote code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-09); latest day: 1
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-02-09: 4Mentions · 2026-02-10: 2Mentions · 2026-03-22: 1Patch / Workaround · 2026-02-10: 2Technical Details · 2026-02-09: 4Technical Details · 2026-02-10: 2Technical Details · 2026-03-22: 102-0902-1003-22
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-094
Disclosure4
2026-02-102
Patch2
2026-03-221
Disclosure1
Full discourse7 posts
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces critical CVEs, details technical aspects, and provides patch and mitigation guidance without evidence of PoC or active exploitation.

    00010105
    64 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-22904 Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger… https://www.cve.org/CVERecord?id=CVE-2026-22904

    Post summary

    The post provides a brief description of CVE-2026-22904, noting improper cookie length handling that could allow an unauthenticated attacker to send oversized cookie values. No PoC, exploit, patch, or active exploitation information is included.

    00010204
    56.5K followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🚨 CVE-2026-22904 (CVSS 9.8): Cookie parsing stack buffer overflow in SmarterMail → unauth RCE via oversized TRACKID. Webmail DoS/RCE! https://feedly.com/cve/severity/9-10?page=6

    Post summary

    The tweet announces a critical buffer‑overflow vulnerability in SmarterMail that allows unauthenticated remote code execution via an oversized TRACKID cookie, potentially leading to denial‑of‑service.

    0000079
    374 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🚨 Critical CVEs Today: Web Services Stack (CVSS 9.8-9.9) Affected: jsonpath (npm); GitLab AI Gateway; Lighttpd Internet-facing risks dominate, driven by pre-auth and unauthenticated exploits across a JSON-path library, a gateway service, and a web server. CVE-2026-1868 (CVSS 9.9) GitLab AI Gateway Duo Workflow Service is affected by insecure template expansion of user-supplied Duo Agent Platform Flow definitions across AI Gateway versions 18.1.6 through 18.8.0, enabling potential DoS or code execution. CVE-2026-1615 (CVSS 9.8) All versions of jsonpath are vulnerable to Arbitrary Code Injection via unsafe evaluation of user-supplied JSON Path expressions. CVE-2026-22903 (CVSS 9.8) A modified lighttpd server can be triggered by an unauthenticated remote attacker sending a crafted HTTP request with an overly long SESSIONID cookie, causing a stack buffer overflow that can crash the service and may enable remote code execution. CVE-2026-22904 (CVSS 9.8) Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated attacker to send oversized cookie values that trigger a stack buffer overflow, leading to denial of service and potential remote code execution. 🛠️ Action • Patch/upgrade GitLab AI Gateway to 18.6.2, 18.7.1, or 18.8.1 (per advisory) and apply vendor updates for impacted components when available • Prioritize internet-facing instances and edge deployments for rapid remediation • For jsonpath (CVE-2026-1615) with no fix yet, apply mitigations such as avoiding evaluation of untrusted JSONPath expressions or sandboxing input; monitor for patches • Add detections for exploitation patterns: suspicious JSONPath input attempts and anomalous script execution in eval paths; monitor relevant logs • Hunt for indicators around the affected services during disclosure-to-now window (logs, EDR, WAF) • Validate remediation (version checks, config verification) and monitor for reversion

    Post summary

    The post announces critical CVEs with detailed technical information and provides clear patch and mitigation guidance, focusing on remediation rather than exploitation.

    0000080
    64 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    ⚠️ CRITICAL: CVE-2026-22904 in WAGO 0852-1322 enables unauthenticated RCE & DoS via stack buffer overflow. Isolate affected devices urgently! 🏭 https://radar.offseq.com/threat/cve-2026-22904-cwe-121-stack-based-buffer-overflow-f7b2d93e #OffSeq #ICS #Vulnerability https://t.co/VadSwZDl6a

    Post summary

    CVE-2026-22904 is a critical stack-based buffer overflow that permits unauthenticated remote code execution and denial of service on WAGO 0852-1322 devices, prompting urgent isolation of affected units.

    0000044
    268 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-22904: CRITICAL] Vulnerability in cookie parsing can lead to denial-of-service and remote code execution by sending oversized cookie values. #CyberSecurity#cve,CVE-2026-22904,#cybersecurity https://cvefind.com/CVE-2026-22904

    Post summary

    A new critical CVE-2026-22904 is disclosed, highlighting a cookie parsing vulnerability that allows DoS and remote code execution via oversized cookie values.

    0000072
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-22904 - Critical Improper length handling when parsing multiple cookie fields (including TRACKID) allows an unauthenticated remote attacker to send oversized cookie values and trigger a stack buffer overf... https://www.thehackerwire.com/vulnerability/CVE-2026-22904/ https://t.co/kOk0F81nkx

    Post summary

    The tweet announces CVE-2026-22904 as a critical stack buffer overflow vulnerability in cookie parsing, providing a brief technical description and linking to an external vulnerability page.

    0000079
    112 followersView on X

Explore more