Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://checkmk.com/werk/22116 |
|
Mon, 21 Sep 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size. | |
| Title | Missing decompression size limit in agent receiver allows memory exhaustion via push agent data | |
| First Time appeared |
Checkmk
Checkmk checkmk |
|
| Weaknesses | CWE-409 | |
| CPEs | cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:* cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:* |
|
| Vendors & Products |
Checkmk
Checkmk checkmk |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Checkmk
Published:
Updated: 2026-09-21T10:57:37.433Z
Reserved: 2026-08-20T08:31:22.429Z
Link: CVE-2026-77021
No data.
Status : Deferred
Published: 2026-09-21T11:17:12.200
Modified: 2026-09-21T11:17:12.360
Link: CVE-2026-77021
No data.
OpenCVE Enrichment
Updated: 2026-09-21T13:15:08Z
