PatchSiren

netdata CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM netdata CVE published 2026-09-22

CVE-2026-83602

CVE-2026-83602 debrief based on CVE Program and NVD records. The vulnerability allows unauthenticated PUT requests to persist attacker-controlled JSON, manipulate its version counter, and consume disk space in Netdata versions from 2.0.0 to 2.11.0. Operators should verify exposure and assess patching priority to prevent potential disk space consumption and configuration manipulation. This issue is fixed i [truncated]

MEDIUM netdata CVE published 2026-09-22

CVE-2026-83601

CVE-2026-83601 debrief: authenticated child agent can cause parent agent crash with oversized DIMENSION SLOT value, allowing potential resource allocation issues and crashes in Netdata versions prior to 2.10.4; verify and apply Netdata version 2.10.4 or later for fix, and review authenticated child agent access and DIMENSION SLOT values for potential security risks and necessary mitigations across affecte [truncated]

MEDIUM netdata CVE published 2026-07-02

CVE-2025-71385

CVE-2025-71385 is a reflected cross-site scripting vulnerability in Netdata before version 2.3.1. The vulnerability exists in the api/v2/ilove.svg and api/v3/ilove.svg endpoints, which reflect user-supplied input from the 'love' query parameter into the generated SVG document without proper escaping. This allows an attacker to inject malicious scripts that execute in the victim's browser within the origin [truncated]