CVE-2026-59783 PUBLISHED

Server DoS via binary items

Assigner: Zabbix
Reserved: 07.07.2026 Published: 05.10.2026 Updated: 05.10.2026

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 2.3

Product Status

Vendor Zabbix
Product Zabbix
Versions Default: unknown
  • affected from 7.0.0 to 7.0.28 (incl.)
  • affected from 7.4.0 to 7.4.12 (incl.)

Affected Configurations

Attacker with trapper access sending malicious data for binary items.

Workarounds

Disable item data collection for any Binary items with untrusted input.

Solutions

Update the affected components to their respective fixed versions.

Credits

  • Zabbix wants to thank ylwango613 for submitting this report on the HackerOne bug bounty platform. reporter

References

Problem Types

  • CWE-787: Out-of-bounds Write CWE

Impacts

  • CAPEC-52: Embedding NULL Bytes