OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-83599

HIGH · CVSS 7.5 EPSS 0.74% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Netdata's unauthenticated WebSocket server prior to version 2.11.0 is vulnerable to a memory exhaustion attack due to improper handling of compressed WebSocket messages, allowing attackers to exploit this flaw to allocate excessive memory on the server. This can lead to service termination and disrupt monitoring capabilities. Organizations using affected versions of Netdata should prioritize upgrading to version 2.11.0 to mitigate this high-severity vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-83599
Severity
HIGH
CVSS
7.5
EPSS
0.74%

Original NVD Description

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed output toward WS_MAX_DECOMPRESSED_SIZE without enforcing a compressed-to-decompressed ratio. Small highly compressed frames can therefore cause large server-side allocations, and repeated concurrent connections can exhaust memory and terminate monitoring. This vulnerability is fixed in 2.11.0.