ExportXMLWordPrintable

    • Type: Defect (Security)
    • Resolution: Fixed
    • Priority: Minor
    • None
    • Affects Version/s: None
    • Component/s: Proxy (P), Server (S)
    • None

      CVE ID CVE-2026-59783
      CVSS score 2.3 (Low)
      CVSS vector CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
      Affected components Server, Proxy
      Summary Server DoS via binary items
      Description The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
      Known attack vectors Attacker with trapper access sending malicious data for binary items.
      Affected and fix version/s Affected: 7.0.0 - 7.0.28 → Fixed: 7.0.29
      Affected: 7.4.0 - 7.4.12 → Fixed: 7.4.13
      Mitigation Update the affected components to their respective fixed versions.
      Workarounds Disable item data collection for any Binary items with untrusted input.
      Acknowledgements Zabbix wants to thank ylwango613 for submitting this report on the HackerOne bug bounty platform.

            Assignee:
            Zabbix Support Team
            Reporter:
            Janis Nulle
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Created:
              Updated:
              Resolved: