CVE-2026-77021
EUVD-2026-8388321.09.2026, 11:17
Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| checkmk | checkmk | 2.5.0 ≤ 𝑥 ≤ 2.5.0p13 | CNA |
| checkmk | checkmk | 2.4.0 ≤ 𝑥 ≤ 2.4.0p36 | CNA |
| checkmk | checkmk | 2.3.0 ≤ 𝑥 ≤ 2.3.0p50 | CNA |
| checkmk | checkmk | 2.2.0 | CNA |
Common Weakness Enumeration
References