Oversized CHART SLOT Vulnerability in Netdata Observability Tool
CVE-2026-83600

6.5MEDIUM

Key Information:

Vendor

Netdata

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-83600?

Netdata, an open-source observability tool, is affected by a vulnerability that allows an authenticated child agent to send an oversized CHART SLOT value. This leads to memory allocation issues as str2ull_encoded requests an excessively large chart-pointer array, which can cause the parent Netdata agent to abort and disable centralized monitoring. This issue has been resolved in version 2.10.4 and nightly build 2.10.0-782-nightly, reinforcing the importance of upgrading to maintain system stability and security.

Affected Version(s)

netdata < 2.10.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.