VYPR
High severity7.5NVD Advisory· Published Sep 22, 2026

CVE-2026-83599

CVE-2026-83599

Description

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed output toward WS_MAX_DECOMPRESSED_SIZE without enforcing a compressed-to-decompressed ratio. Small highly compressed frames can therefore cause large server-side allocations, and repeated concurrent connections can exhaust memory and terminate monitoring. This vulnerability is fixed in 2.11.0.

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.