CVE-2026-23935 PUBLISHED

Use-after-free read in script item/preprocessing HttpRequest body

Assigner: Zabbix
Reserved: 19.01.2026 Published: 18.08.2026 Updated: 18.08.2026

A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 7.0.0 to 7.0.27 (incl.)
  • affected from 7.4.0 to 7.4.11 (incl.)

Affected Configurations

An authenticated administrator using specifically crafted script item or JavaScript preprocessing scripts.

Solutions

Update the affected components to their respective fixed versions.

Credits

  • Zabbix wants to thank Aikido Security for submitting this report on the HackerOne bug bounty platform. reporter

References

Problem Types

  • CWE-125: Out-of-bounds Read CWE

Impacts

  • CAPEC-540: Overread Buffers