Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. The accepted slot drives
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-83603 | 8.4 HIGH | Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE |
| CVE-2026-83598 | 7.8 HIGH | Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Prof |
| CVE-2026-83599 | 7.5 HIGH | Netdata: WebSocket Decompression Bomb |
| CVE-2026-83597 | 7.0 HIGH | Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Exec |
| CVE-2026-83601 | 6.5 MEDIUM | Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer over |
| CVE-2026-83602 | 6.5 MEDIUM | Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via |
No comments yet