Description
Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
Published: 2026-09-21
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Memory Exhaustion (Denial of Service)
Action: Patch Immediately
AI Analysis

Impact

The vulnerability arises from improper handling of highly compressed data in Checkmk. An attacker who controls a host registered for push mode can send a tiny zlib‑compressed payload that expands during decompression to an arbitrary size, exhausting the memory of the agent receiver. This resource exhaustion can cause the agent to become unresponsive or crash, resulting in a denial of service. The weakness is classified as CWE-409.

Affected Systems

Checkmk GmbH’s Checkmk product is affected. All versions released before 2.5.0p14, before 2.4.0p37, before 2.3.0p51, and the 2.2.0 release (which is end‑of‑life) are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. An EPSS score is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, as the attacker must control a host registered for push mode to exploit the flaw. Successful exploitation would result in memory exhaustion of the agent receiver but does not directly compromise data confidentiality or integrity.

Generated by OpenCVE AI on September 21, 2026 at 12:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Checkmk to a supported version ≥ 2.5.0p14, ≥ 2.4.0p37 or ≥ 2.3.0p51.
  • If still on 2.2.0, migrate to a supported release or discontinue use of that version.
  • Disable or restrict push mode until an upgrade can be performed, limiting who can register and send data to the agent receiver.

Generated by OpenCVE AI on September 21, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 21 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
Title Missing decompression size limit in agent receiver allows memory exhaustion via push agent data
First Time appeared Checkmk
Checkmk checkmk
Weaknesses CWE-409
CPEs cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:2.2.0:*:*:*:*:*:*:*
Vendors & Products Checkmk
Checkmk checkmk
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published:

Updated: 2026-09-21T10:57:37.433Z

Reserved: 2026-08-20T08:31:22.429Z

Link: CVE-2026-77021

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-21T11:17:12.200

Modified: 2026-09-21T11:17:12.360

Link: CVE-2026-77021

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T12:30:14Z

Weaknesses
  • CWE-409

    Improper Handling of Highly Compressed Data (Data Amplification)