Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

netdata — Vulnerabilities & Security Advisories 11

Browse all 11 CVE security advisories affecting netdata. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Netdata provides real-time monitoring and observability for IT infrastructure, enabling performance tracking and anomaly detection. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from insufficient input validation and authentication flaws. The project maintains a security-focused development approach, with rapid response to reported issues. While no major public incidents have been documented, the three CVEs on record highlight potential risks in web interface components and data collection mechanisms. Regular updates and hardening configurations are recommended to mitigate exposure.

Found 11 results / 11 Clear Filters
Top products by netdata: netdata
CVE ID Title CVSS Severity Published
CVE-2026-83597 Netdata: Local Privilege Escalation in Netdata Windows Agent installer via MSI Repair Execution — netdata CWE-269 7.0 High 2026-09-22
CVE-2026-83600 Netdata: Streaming protocol chart slot guard off-by-one allows ~16 GiB allocation request, crashing parent agent — netdata CWE-193 6.5 Medium 2026-09-22
CVE-2026-83598 Netdata: Local Privilege Escalation in Netdata Agent Windows installer via PowerShell Profile Hijack in MSI Repair — netdata CWE-269 7.8 High 2026-09-22
CVE-2026-83603 Netdata: Local Root via ndsudo Arbitrary socket_path → fail2ban-client Pickle RCE — netdata CWE-73 8.4 High 2026-09-22
CVE-2026-83601 Netdata: Streaming protocol dimension slot has no upper-bound guard, allowing integer overflow and out-of-bounds write — netdata CWE-190 6.5 Medium 2026-09-22
CVE-2026-83602 Netdata: Unauthenticated remote PUT to /api/v3/settings bypasses IP allowlist controls via HTTP_ACL_NOCHECK — netdata CWE-284 6.5 Medium 2026-09-22
CVE-2026-83599 Netdata: WebSocket Decompression Bomb — netdata CWE-409 7.5 High 2026-09-22
CVE-2025-71385 Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.svg Endpoint — netdata CWE-79 6.1 Medium 2026-07-02
CVE-2024-32019 ndsudo: local privilege escalation via untrusted search path — netdata CWE-426 8.8 High 2024-04-12
CVE-2023-22497 Netdata is vulnerable to improper authentication — netdata CWE-287 6.5 Medium 2023-01-14
CVE-2023-22496 Netdata vulnerable to command injection — netdata CWE-20 8.1 High 2023-01-14

This page lists every published CVE security advisory associated with netdata. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.