Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the affected components to their respective fixed versions.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-27284 |
|
Fri, 06 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix frontend
|
|
| CPEs | cpe:2.3:a:zabbix:frontend:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Zabbix frontend
|
|
| Metrics |
cvssV3_1
|
Mon, 01 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zabbix
Zabbix zabbix |
|
| Vendors & Products |
Zabbix
Zabbix zabbix |
Mon, 01 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service. | |
| Title | Frontend DoS vulnerability due to asymmetric resource consumption | |
| Weaknesses | CWE-405 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2025-12-01T14:34:20.496Z
Reserved: 2025-06-09T12:23:32.445Z
Link: CVE-2025-49643
Updated: 2025-12-01T14:34:11.678Z
Status : Analyzed
Published: 2025-12-01T14:16:06.007
Modified: 2026-02-06T15:28:30.470
Link: CVE-2025-49643
No data.
OpenCVE Enrichment
Updated: 2025-12-01T21:27:33Z