Search CVE reports


Toggle filters

1 – 10 of 20 results


CVE-2026-83597

Medium priority
Needs evaluation

Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83603

Medium priority
Needs evaluation

Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83602

Medium priority
Needs evaluation

Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83601

Medium priority
Needs evaluation

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83600

Medium priority
Needs evaluation

Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83599

Medium priority
Needs evaluation

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-83598

Medium priority
Needs evaluation

Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-71385

Medium priority
Needs evaluation

Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text element) without HTML or XML escaping, and...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2024-34251

Medium priority

Some fixes available 1 of 2

An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not affected Not affected Not affected Not affected
Show less packages

CVE-2024-34250

Medium priority

Some fixes available 1 of 2

A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function...

1 affected package

netdata

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
netdata Not affected Not affected Not affected Not affected
Show less packages