Impact
A stack overflow occurs when Icinga 2 parses deeply nested JSON objects; the depth limit is not enforced, allowing the call stack to be exhausted and the process to crash. The flaw does not currently enable arbitrary code execution but does lead to a denial‑of‑service condition for the monitored host.
Affected Systems
Vendors: Icinga; Product: Icinga 2. Versions earlier than 2.14.9, 2.15.4, or 2.16.2 are affected. Any deployment running those releases without the corresponding patch is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the attack surface is high because the weakened code path is reachable by any unauthenticated network client on TCP port 5665. A remote attacker could repeatedly send malicious JSON to exhaust the stack and crash the service, potentially disrupting monitoring and alert delivery. The simplicity of the required payload and the absence of authentication make exploitation straightforward for an adversary with network visibility to the Icinga 2 endpoint.
OpenCVE Enrichment
Debian DSA