VYPR

Netdata

by Netdata

Source repositories

CVEs (16)

  • CVE-2023-22496HigJan 14, 2023
    risk 0.56cvss 8.1epss 0.36

    Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent. When an alert is triggered, the function…

  • CVE-2024-32019HigApr 12, 2024
    risk 0.53cvss 8.8epss 0.01

    Netdata is an open source observability tool. In affected versions the `ndsudo` tool shipped with affected versions of the Netdata Agent allows an attacker to run arbitrary programs with root permissions. The `ndsudo` tool is packaged as a `root`-owned executable with the SUID…

  • CVE-2018-18838HigJun 18, 2019
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter to api/v1/registry.

  • CVE-2026-83603HigSep 22, 2026
    risk 0.48cvss 8.4epss 0.00

    Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-status-socket in src/collectors/utils/ndsudo.c accepts a caller-controlled --socket_path from the low-privileged netdata service account. The account can direct…

  • CVE-2026-83598HigSep 22, 2026
    risk 0.44cvss 7.8epss 0.00

    Netdata is an open source observability tool. From rom 2.0.0 until 2.10.4, during Netdata Windows Agent MSI repair, powershell.exe runs as SYSTEM without -NoProfile and loads %USERPROFILE%\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 from the low-privileged user…

  • CVE-2019-9834MedMar 15, 2019
    risk 0.43cvss 6.1epss 0.06

    The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation will allow attacker-supplied HTML to run in the context of the affected browser, potentially allowing…

  • CVE-2026-83599HigSep 22, 2026
    risk 0.42cvss 7.5epss 0.01

    Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed output…

  • CVE-2023-22497MedJan 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when the agent first starts and it is saved to disk, so that it will persist across restarts and reboots.…

  • CVE-2018-18836MedJun 18, 2019
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_request_v1_data in web/api/web_api_v1.c.

  • CVE-2018-18837MedJun 18, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in Netdata 1.10.0. HTTP Header Injection exists via the api/v1/data filename parameter because of web_client_api_request_v1_data in web/api/web_api_v1.c.

  • CVE-2026-83597HigSep 22, 2026
    risk 0.38cvss 7.0epss 0.00

    Netdata is an open source observability tool. From version 2.0.0 until 2.10.4, Netdata Windows Agent MSI repair launches powershell.exe and wevtutil.exe as elevated interactive processes in the initiating user's desktop session. A low-privileged local user who triggers repair…

  • CVE-2026-83602MedSep 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Netdata is an open source observability tool. From 2.0.0 until 2.11.0, Netdata registers /api/v3/settings in src/web/api/v3/web_api_v3.c with HTTP_ACL_NOCHECK and HTTP_ACCESS_ANONYMOUS_DATA, causing unauthenticated PUT requests handled by src/web/api/v3/api_v3_settings.c to…

  • CVE-2026-83601MedSep 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized DIMENSION SLOT value that str2ull_encoded passes to pluginsd_rrddim_put_to_slot in src/plugins.d/pluginsd_internals.h without an upper bound. prd_array_create in…

  • CVE-2026-83600MedSep 22, 2026
    risk 0.35cvss 6.5epss 0.01

    Netdata is an open source observability tool. Prior to 2.10.4, an authenticated child agent can send an oversized CHART SLOT value that str2ull_encoded passes to pluginsd_rrdset_cache_put_to_slot in src/plugins.d/pluginsd_internals.h. The accepted slot drives reallocz to request…

  • CVE-2018-18839MedJun 18, 2019
    risk 0.35cvss 5.3epss 0.02

    An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional.

  • CVE-2025-71385MedJul 2, 2026
    risk 0.33cvss 6.1epss 0.00

    Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text element) without HTML or XML escaping, and serves the response with Content-Type image/svg+xml. An…