| Release | Version |
|---|---|
| bookworm | 287.1-0+deb12u3 |
| bookworm (security) | 287.1-0+deb12u2 |
| trixie | 337-1+deb13u2 |
| forky | 367-1 |
| sid | 367-1 |
| Bug | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|
| CVE-2026-76235 | vulnerable | fixed | fixed | fixed | A memory leak flaw was found in cockpit-ws. The login page handler lea ... |
| CVE-2026-4802 | vulnerable (no DSA, postponed) | fixed | fixed | fixed | A flaw was found in Cockpit. This vulnerability allows a remote attack ... |
| Bug | Description |
|---|---|
| CVE-2026-4631 | Cockpit's remote login feature passes user-supplied hostnames and user ... |
| CVE-2024-6126 | A flaw was found in the cockpit package. This flaw allows an authentic ... |
| CVE-2024-2947 | A flaw was found in Cockpit. Deleting a sosreport with a crafted name ... |
| CVE-2021-3698 | A flaw was found in Cockpit in versions prior to 260 in the way it han ... |
| CVE-2021-3660 | Cockpit (and its plugins) do not seem to protect itself against clickj ... |
| CVE-2019-3804 | It was found that cockpit before version 184 used glib's base64 decode ... |
| DSA / DLA | Description |
|---|---|
| DSA-6474-1 | cockpit - security update |
| DSA-5655-2 | cockpit - regression update |
| DSA-5655-1 | cockpit - security update |