CVE-2026-88831: Not Failing Securely ('Failing Open') in Red Hat Red Hat Hardened Images
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
AI Analysis
Technical Summary
This vulnerability arises because BusyBox httpd does not fail securely when IP deny rules contain invalid CIDR prefix lengths. Instead of blocking access, the server parses the IP with a zeroed mask, effectively matching no clients and allowing unintended access. This is a failure to enforce intended access restrictions, categorized under CWE-636 (Not Failing Securely). The issue requires a misconfiguration in the httpd configuration file and is specific to BusyBox httpd as shipped in Red Hat Hardened Images. Red Hat advises auditing all BusyBox httpd configuration files for valid CIDR prefix lengths and recommends using network-level access controls as the primary enforcement mechanism.
Potential Impact
The vulnerability allows bypassing of intended IP-based access restrictions in BusyBox httpd, potentially permitting unauthorized network clients to access protected content. There is no impact on integrity or availability, and no privileges or user interaction are required for exploitation. The overall confidentiality impact is low.
Mitigation Recommendations
Red Hat advises auditing all BusyBox httpd configuration files to ensure CIDR prefix lengths are syntactically valid. Additionally, network-level access controls such as iptables or nftables should be implemented as the primary enforcement layer rather than relying solely on application-level ACLs. No official fix or patch status is provided in the advisory; therefore, patch status is not yet confirmed—check the Red Hat advisory for updates.
CVE-2026-88831: Not Failing Securely ('Failing Open') in Red Hat Red Hat Hardened Images
Description
BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the rule matches no clients.
CVSS v3.1
Score 5.3medium
Affected software
Red Hat
Red Hat Hardened Images
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises because BusyBox httpd does not fail securely when IP deny rules contain invalid CIDR prefix lengths. Instead of blocking access, the server parses the IP with a zeroed mask, effectively matching no clients and allowing unintended access. This is a failure to enforce intended access restrictions, categorized under CWE-636 (Not Failing Securely). The issue requires a misconfiguration in the httpd configuration file and is specific to BusyBox httpd as shipped in Red Hat Hardened Images. Red Hat advises auditing all BusyBox httpd configuration files for valid CIDR prefix lengths and recommends using network-level access controls as the primary enforcement mechanism.
Potential Impact
The vulnerability allows bypassing of intended IP-based access restrictions in BusyBox httpd, potentially permitting unauthorized network clients to access protected content. There is no impact on integrity or availability, and no privileges or user interaction are required for exploitation. The overall confidentiality impact is low.
Mitigation Recommendations
Red Hat advises auditing all BusyBox httpd configuration files to ensure CIDR prefix lengths are syntactically valid. Additionally, network-level access controls such as iptables or nftables should be implemented as the primary enforcement layer rather than relying solely on application-level ACLs. No official fix or patch status is provided in the advisory; therefore, patch status is not yet confirmed—check the Red Hat advisory for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-10T09:42:04.559Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-88831","vendor":"Red Hat"}]
Threat ID: 6ab410edf7a7c541061ebb07
Added to database: 09/23/2026, 17:48:29 UTC
Last enriched: 09/23/2026, 18:03:23 UTC
Last updated: 09/24/2026, 01:57:04 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.