Data Amplification Vulnerability in Checkmk Products
CVE-2026-77021
5.3MEDIUM
What is CVE-2026-77021?
An attacker can exploit a vulnerability in Checkmk versions prior to 2.5.0p14, 2.4.0p37, and 2.3.0p51, as well as the End of Life version 2.2.0, by sending a specially crafted zlib compressed payload that decompresses to an arbitrary size. This improper handling of highly compressed data allows the attacker to exhaust the memory resources of the agent receiver, leading to potential denial-of-service conditions. Organizations using affected versions should implement necessary security measures and consider updates to mitigate this risk.
Affected Version(s)
Checkmk 2.5.0 < 2.5.0p14
Checkmk 2.4.0 < 2.4.0p37
Checkmk 2.3.0 < 2.3.0p51
