Zabbix Server and Proxy Denial-of-Service Vulnerability Due to Uncontrolled Resource Exhaustion

Vulnerability

A denial-of-service vulnerability has been identified in Zabbix Server and Zabbix Proxy, versions 6.0.0 through 6.0.38, 7.0.0 through 7.0.9, and 7.2.0 through 7.2.3. This vulnerability allows an attacker to send specially crafted requests that cause the server to excessively allocate memory and engage in CPU-intensive decompression tasks, leading to a service crash.

Impact

Exploitation of this vulnerability causes the Zabbix server or proxy to crash, disrupting service.

Remediation

Users can upgrade to Zabbix versions 6.0.39rc1, 7.0.10rc1, or 7.2.4rc1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.