Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow de
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-83603 | 8.4 HIGH | Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE |
| CVE-2026-83598 | 7.8 HIGH | Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Prof |
| CVE-2026-83597 | 7.0 HIGH | Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Exec |
| CVE-2026-83601 | 6.5 MEDIUM | Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer over |
| CVE-2026-83602 | 6.5 MEDIUM | Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via |
| CVE-2026-83600 | 6.5 MEDIUM | Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, |
No comments yet