PT-2026-96846 · Netdata · Netdata

CVE-2026-83600

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Netdata versions prior to 2.10.4
Description An authenticated child agent can send an oversized CHART SLOT value that is processed by the str2ull encoded function and passed to pluginsd rrdset cache put to slot in src/plugins.d/pluginsd internals.h. This causes reallocz to request a chart-pointer array of approximately 16 GiB. The resulting allocation failure triggers a fatal error that aborts the parent Netdata agent, leading to the repeated disabling of centralized monitoring while stream access remains active.
Recommendations Update to version 2.10.4 or nightly build 2.10.0-782-nightly.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-83600
GHSA-3MXW-FV2X-RHC6

Affected Products

Netdata