CVE-2026-59783

Description

A flaw was found in Zabbix Server and Proxy. In deployments configured with a MySQL or MariaDB database backend, an authenticated remote attacker can cause a denial of service (DoS) by submitting binary items containing null bytes. This improper input handling causes the server or proxy process to crash, leading to a loss of monitoring service availability.

Statement

Red Hat does not ship Zabbix in any supported product. The community EPEL zabbix7.0 package is affected by this flaw and a community tracker has been filed.

Mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Application Data

Generally this error will cause the data structure to not work properly by truncating the data.

Frequently Asked Questions

Want to get errata notifications? Sign up here.