Denial of Service Vulnerability in Zabbix Web Application
CVE-2025-49643

6MEDIUM

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
1 December 2025

What is CVE-2025-49643?

An authenticated user, including Guest accounts, can exploit a flaw in the Zabbix web application by sending specially crafted parameters to the /imgstore.php endpoint. This can lead to a significant increase in CPU load on the web server, ultimately resulting in potential denial of service. It is crucial for users to properly secure their Zabbix installations to mitigate this threat.

Affected Version(s)

Zabbix 6.0.0 <= 6.0.41

Zabbix 7.0.0 <= 7.0.18

Zabbix 7.2.0 <= 7.2.12

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zabbix wants to thank Pamparau Sebastian (sebiee) for submitting this report on the HackerOne bug bounty platform.
.
CVE-2025-49643 : Denial of Service Vulnerability in Zabbix Web Application