Impact
Netdata allows unauthenticated clients to negotiate WebSocket compression before authentication. The server decompresses incoming frames without enforcing a strong ratio check, permitting small compressed frames to expand to large uncompressed payloads. This uncontrolled allocation can cause rapid memory growth and eventually terminate the monitoring process or degrade overall system performance.
Affected Systems
The vulnerability affects all installations of Netdata earlier than version 2.11.0. The product is the Netdata observability platform; any deployment that has the default WebSocket interface enabled is susceptible.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. Because the exploit requires only a WebSocket connection, an attacker can trigger the memory exhaustion from a remote location without prior authentication. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and the ability to exhaust memory make it a practical concern for any exposed Netdata instance.
OpenCVE Enrichment