CVE-2026-88831 is a vulnerability in Red Hat Hummingbird
Published on September 23, 2026
Busybox: busybox: httpd silently fails open when ip deny rules contain invalid cidr prefix lengths
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
Vulnerability Analysis
CVE-2026-88831 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity and availability.
Timeline
Reported to Red Hat.
Made public. 14 days later.
Weakness Type
What is a Failing Open Vulnerability?
When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions. By entering a less secure state, the product inherits the weaknesses associated with that state, making it easier to compromise. At the least, it causes administrators to have a false sense of security. This weakness typically occurs as a result of wanting to "fail functional" to minimize administration and support costs, instead of "failing safe."
CVE-2026-88831 has been classified to as a Failing Open vulnerability or weakness.
Products Associated with CVE-2026-88831
Want to know whenever a new CVE is published for Red Hat Hummingbird? stack.watch will email you.