Debian Package Tracker
Register | Log in
Subscribe

cockpit

Web Console for Linux servers

Choose email to subscribe with

general
  • source: cockpit (main)
  • version: 367-1
  • maintainer: Utopia Maintenance Team (archive) (DMD)
  • uploaders: Michael Biebl [DMD] – Martin Pitt [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 239-1
  • oldstable: 287.1-0+deb12u3
  • old-sec: 287.1-0+deb12u2
  • old-bpo: 337-1~bpo12+1
  • stable: 337-1+deb13u1
  • stable-sec: 337-1+deb13u2
  • stable-bpo: 366-1~bpo13+1
  • stable-p-u: 337-1+deb13u2
  • testing: 366-1
  • unstable: 367-1
versioned links
  • 239-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 287.1-0+deb12u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 287.1-0+deb12u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 337-1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 337-1+deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 337-1+deb13u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 365-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 366-1~bpo13+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 366-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 367-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • cockpit
  • cockpit-bridge
  • cockpit-doc
  • cockpit-networkmanager
  • cockpit-packagekit
  • cockpit-sosreport
  • cockpit-storaged
  • cockpit-system
  • cockpit-ws
action needed
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-76235: A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
1 issue postponed or untriaged:
  • CVE-2026-4802: (postponed; to be fixed through a stable update) A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
Created: 2026-08-19 Last update: 2026-09-01 22:00
5 security issues in bullseye high

There are 5 open security issues in bullseye.

1 important issue:
  • CVE-2026-76235: A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLang cookie, allowing a remote unauthenticated attacker to exhaust memory on the host and cause a denial of service.
2 issues postponed or untriaged:
  • CVE-2021-3698: (needs triaging) A flaw was found in Cockpit in versions prior to 260 in the way it handles the certificate verification performed by the System Security Services Daemon (SSSD). This flaw allows client certificates to authenticate successfully, regardless of the Certificate Revocation List (CRL) configuration or the certificate status. The highest threat from this vulnerability is to confidentiality.
  • CVE-2026-4802: (postponed; to be fixed through a stable update) A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the host by exploiting unsanitized user-controlled parameters within crafted links in the system logs user interface (UI). An attacker can inject shell metacharacters and command substitutions into these parameters, leading to the execution of arbitrary shell commands on the affected system. This could result in a complete system compromise.
2 ignored issues:
  • CVE-2021-3660: Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to render a page from a cockpit server via another website, inside an <iFrame> HTML entry. This may be used by a malicious website in clickjacking or similar attacks.
  • CVE-2024-6126: A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
Created: 2026-08-19 Last update: 2026-08-30 12:02
The package has not entered testing even though the delay is over normal
The package has not entered testing even though the 2-day delay is over. Check why.
Created: 2026-09-03 Last update: 2026-09-03 09:02
AppStream hints: 1 warning for cockpit normal
AppStream found metadata issues for packages:
  • cockpit: 1 warning
You should get rid of them to provide more metadata about this software.
Created: 2026-08-24 Last update: 2026-08-24 09:00
testing migrations
  • excuses:
    • Migration status for cockpit (366-1 to 367-1): Will attempt migration (Any information below is purely informational)
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/c/cockpit.html
    • ∙ ∙ Autopkgtest for cockpit/367-1: amd64: Pass, arm64: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, riscv64: Pass
    • ∙ ∙ Autopkgtest for cockpit-podman/129-1: i386: Pass ♻ (reference ♻)
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • ∙ ∙ Required age reduced by 3 days because of autopkgtest
    • ∙ ∙ 4 days old (needed 2 days)
news
[rss feed]
  • [2026-08-31] Accepted cockpit 337-1+deb13u2 (source) into proposed-updates (Debian FTP Masters) (signed by: Martin Pitt)
  • [2026-08-30] cockpit 366-1 MIGRATED to testing (Debian testing watch)
  • [2026-08-30] Accepted cockpit 367-1 (source) into unstable (Martin Pitt)
  • [2026-08-30] Accepted cockpit 366-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-08-27] Accepted cockpit 337-1+deb13u2 (source) into stable-security (Debian FTP Masters) (signed by: Martin Pitt)
  • [2026-08-21] Accepted cockpit 366-1 (source) into unstable (Martin Pitt)
  • [2026-08-03] Accepted cockpit 365-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-08-03] cockpit 365-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-31] Accepted cockpit 365-1 (source) into unstable (Martin Pitt)
  • [2026-05-31] Accepted cockpit 362-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-05-31] cockpit 362-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-29] Accepted cockpit 362-1 (source) into unstable (Martin Pitt)
  • [2026-05-03] Accepted cockpit 337-1+deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Martin Pitt)
  • [2026-04-12] Accepted cockpit 360-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-04-12] cockpit 360-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-09] Accepted cockpit 360-1 (source) into unstable (Martin Pitt)
  • [2026-03-22] Accepted cockpit 358-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-03-21] cockpit 358-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-19] Accepted cockpit 358-1 (source) into unstable (Martin Pitt)
  • [2026-02-19] Accepted cockpit 356-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-02-19] cockpit 356-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-11] Accepted cockpit 356-1 (source) into unstable (Martin Pitt)
  • [2026-01-31] Accepted cockpit 355-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-01-31] cockpit 355-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-29] Accepted cockpit 355-1 (source) into unstable (Martin Pitt)
  • [2026-01-17] Accepted cockpit 354-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2026-01-09] cockpit 354-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-07] Accepted cockpit 354-1 (source) into unstable (Martin Pitt)
  • [2025-12-18] Accepted cockpit 353.1-1~bpo13+1 (source) into stable-backports (Martin Pitt)
  • [2025-12-18] cockpit 353.1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 1
  • RC: 0
  • I&N: 0
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 97)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 365-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing