Junglewise Threat Intelligence

CVE-2026-77021: Checkmk agent receiver memory exhaustion via compressed data amplification

CVE-2026-77021 · Severity: info · Published 2026-09-21

Vendors: Checkmk.

Executive brief

Checkmk's agent receiver processes monitoring data from managed hosts using compression to reduce network traffic. An attacker controlling a host registered for push mode can send a small compressed payload that decompresses to an extremely large size, exhausting the receiver's memory and causing a denial of service. The vulnerability requires the attacker to have a valid host certificate for the push mode protocol.

Technical details

The agent receiver decompresses zlib-compressed agent data without enforcing a limit on the decompressed output size, allowing a zip bomb style attack where small payloads expand orders of magnitude. An authenticated attacker (one with a valid host certificate for push mode) can send specially crafted compressed data that causes memory exhaustion. The fix limits decompressed data to 512 MiB and rejects oversized payloads.

Affected products

  • Checkmk Checkmk Ultimate before 2.5.0p14, before 2.4.0p37, before 2.3.0p51, 2.2.0
  • Checkmk Checkmk Cloud before 2.5.0p14, before 2.4.0p37, before 2.3.0p51
  • Checkmk Checkmk Ultimate MT before 2.5.0p14, before 2.4.0p37, before 2.3.0p51

Timeline

  • 2026-09-21: disclosed: Public vulnerability disclosure

References

Related threats