Checkmk · Checkmk · CVE-2026-77021
**Name of the Vulnerable Software and Affected Versions**
Checkmk versions prior to 2.5.0p14
Checkmk versions prior to 2.4.0p37
Checkmk versions prior to 2.3.0p51
Checkmk version 2.2.0
**Description**
Improper handling of highly compressed data, known as data amplification, allows an attacker controlling a host registered for push mode to exhaust the memory of the agent receiver. This is achieved by sending a small zlib compressed payload that decompresses to an arbitrary size.
**Recommendations**
Update to version 2.5.0p14 or later.
Update to version 2.4.0p37 or later.
Update to version 2.3.0p51 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.