Description
Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Exhaustion (Denial of Service)
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from improper handling of highly compressed data in Checkmk. An attacker who controls a host registered for push mode can send a tiny zlib‑compressed payload that expands during decompression to an arbitrary size, exhausting the memory of the agent receiver. This resource exhaustion can cause the agent to become unresponsive or crash, resulting in a denial of service. The weakness is classified as CWE-409.

Affected Systems

Checkmk GmbH’s Checkmk product is affected. All versions released before 2.5.0p14, before 2.4.0p37, before 2.3.0p51, and the 2.2.0 release (which is end‑of‑life) are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. An EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, as the attacker must control a host registered for push mode to exploit the flaw. Successful exploitation would result in memory exhaustion of the agent receiver but does not directly compromise data confidentiality or integrity.

Generated by OpenCVE AI on September 21, 2026 at 12:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Checkmk to a supported version ≥ 2.5.0p14, ≥ 2.4.0p37 or ≥ 2.3.0p51.
  • If still on 2.2.0, migrate to a supported release or discontinue use of that version.
  • Disable or restrict push mode until an upgrade can be performed, limiting who can register and send data to the agent receiver.

Generated by OpenCVE AI on September 21, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
Title Missing decompression size limit in agent receiver allows memory exhaustion via push agent data
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-409
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-09-21T19:40:26.202Z

Reserved: 2026-08-20T08:31:22.429Z

Link: CVE-2026-77021

cve-icon Vulnrichment

Updated: 2026-09-21T19:34:31.547Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T11:17:12.200

Modified: 2026-09-21T20:17:32.393

Link: CVE-2026-77021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T13:15:08Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)