CVE-2026-83602 debrief based on CVE Program and NVD records. The vulnerability allows unauthenticated PUT requests to persist attacker-controlled JSON, manipulate its version counter, and consume disk space in Netdata versions from 2.0.0 to 2.11.0. Operators should verify exposure and assess patching priority to prevent potential disk space consumption and configuration manipulation. This issue is fixed i [truncated]
CVE-2026-83601 debrief: authenticated child agent can cause parent agent crash with oversized DIMENSION SLOT value, allowing potential resource allocation issues and crashes in Netdata versions prior to 2.10.4; verify and apply Netdata version 2.10.4 or later for fix, and review authenticated child agent access and DIMENSION SLOT values for potential security risks and necessary mitigations across affecte [truncated]
CVE-2025-71385 is a reflected cross-site scripting vulnerability in Netdata before version 2.3.1. The vulnerability exists in the api/v2/ilove.svg and api/v3/ilove.svg endpoints, which reflect user-supplied input from the 'love' query parameter into the generated SVG document without proper escaping. This allows an attacker to inject malicious scripts that execute in the victim's browser within the origin [truncated]