Open Source Monitoring System Icinga 2 Vulnerability in JSON Parsing
CVE-2026-61551
8.6HIGH
What is CVE-2026-61551?
Icinga 2, an open source monitoring solution, has been found to have a vulnerability in its JSON parsing mechanism. The issue lies in the lack of bounds on the depth of nested JSON processing. This flaw can be exploited by unauthenticated clients connected to the service on TCP port 5665, potentially leading to a crash of the Icinga 2 process. Although there has been no demonstration of code execution via this vulnerability, it highlights a significant risk in system stability. The vulnerability has been addressed in versions 2.14.9, 2.15.4, and 2.16.2, offering users improvements for enhanced protection.
Affected Version(s)
icinga2 < 2.14.9 < 2.14.9
icinga2 >= 2.15.0, < 2.15.4 < 2.15.0, 2.15.4
icinga2 >= 2.16.0, < 2.16.2 < 2.16.0, 2.16.2
