Description
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the affected components to their respective fixed versions.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28073 |
|
History
Tue, 18 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss. | |
| Title | Use-after-free read in script item/preprocessing HttpRequest body | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-08-18T13:34:59.670Z
Reserved: 2026-01-19T14:03:13.686Z
Link: CVE-2026-23935
No data.
Status : Received
Published: 2026-08-18T13:17:21.843
Modified: 2026-08-18T13:17:21.843
Link: CVE-2026-23935
No data.
OpenCVE Enrichment
No data.
Weaknesses