Description
The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Published: 2026-10-05
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the Zabbix Server/Proxy allows specially crafted binary items that contain null byte input to trigger a crash of the server process, causing a loss of availability for the monitoring system. The weakness is categorized as an out‑of‑bounds write (CWE-787) and can lead to denial of service if an attacker can supply the vulnerable payload to a monitored item.

Affected Systems

Deployments of Zabbix Server or Proxy that use MySQL or MariaDB as the backend database are affected; the specific fixed versions are not listed in the public data for this CVE.

Risk and Exploitability

The CVSS score of 2.3 indicates low overall severity, and there is no EPSS data or KEV listing for this issue. The likely attack vector involves the delivery of the payload through a binary item configured to collect data from an untrusted source. Although the risk of exploitation is low, any successful crash would interrupt monitoring and alerting services, impacting availability.

Generated by OpenCVE AI on October 5, 2026 at 11:22 UTC.

Remediation

Vendor Solution

Update the affected components to their respective fixed versions.


Vendor Workaround

Disable item data collection for any Binary items with untrusted input.


OpenCVE Recommended Actions

  • Update the Zabbix Server or Proxy to a version that includes the vendor fix
  • Disable data collection for all Binary items that receive untrusted input as a temporary workaround
  • Configure Binary item templates to accept data only from trusted sources and review existing items for potential exposure

Generated by OpenCVE AI on October 5, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Zabbix
Zabbix zabbix
Vendors & Products Zabbix
Zabbix zabbix

Mon, 05 Oct 2026 10:45:00 +0000

Type Values Removed Values Added
Description The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.
Title Server DoS via binary items
Weaknesses CWE-787
References
Metrics cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2026-10-05T11:50:08.690Z

Reserved: 2026-07-07T08:30:49.859Z

Link: CVE-2026-59783

cve-icon Vulnrichment

Updated: 2026-10-05T11:47:02.917Z

cve-icon NVD

Status : Received

Published: 2026-10-05T11:16:59.513

Modified: 2026-10-05T12:17:09.993

Link: CVE-2026-59783

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T11:30:17Z

Weaknesses