πŸ” CVE Alert

CVE-2026-77021

UNKNOWN 0.0

Missing decompression size limit in agent receiver allows memory exhaustion via push agent data

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.

CWE CWE-409
Vendor checkmk gmbh
Product checkmk
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for checkmk gmbh checkmk

Be the first to know when new unknown vulnerabilities affecting checkmk gmbh checkmk are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

Checkmk GmbH / Checkmk
2.5.0 < 2.5.0p14 2.4.0 < 2.4.0p37 2.3.0 < 2.3.0p51 2.2.0

References

NVD β†— CVE.org β†— EPSS Data β†—
checkmk.com: https://checkmk.com/werk/22116

Credits

πŸ” Sven JΓ€ger (SySS GmbH)