Memory Allocation Flaw in Netdata Open Source Observability Tool
CVE-2026-83599

7.5HIGH

Key Information:

Vendor

Netdata

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-83599?

The Netdata observability tool has a vulnerability related to its unauthenticated WebSocket server. Prior to version 2.11.0, the server was prone to excessive memory allocation due to a flaw in the handling of per-message deflate negotiations. This security issue allows small, highly compressed frames to produce large allocations on the server-side, potentially leading to memory exhaustion and monitoring disruptions. The vulnerability was addressed in the 2.11.0 release.

Affected Version(s)

netdata < 2.11.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.