Executive brief
Checkmk's agent receiver processes monitoring data from managed hosts using compression to reduce network traffic. An attacker controlling a host registered for push mode can send a small compressed payload that decompresses to an extremely large size, exhausting the receiver's memory and causing a denial of service. The vulnerability requires the attacker to have a valid host certificate for the push mode protocol.
Technical details
The agent receiver decompresses zlib-compressed agent data without enforcing a limit on the decompressed output size, allowing a zip bomb style attack where small payloads expand orders of magnitude. An authenticated attacker (one with a valid host certificate for push mode) can send specially crafted compressed data that causes memory exhaustion. The fix limits decompressed data to 512 MiB and rejects oversized payloads.
Affected products
- Checkmk Checkmk Ultimate before 2.5.0p14, before 2.4.0p37, before 2.3.0p51, 2.2.0
- Checkmk Checkmk Cloud before 2.5.0p14, before 2.4.0p37, before 2.3.0p51
- Checkmk Checkmk Ultimate MT before 2.5.0p14, before 2.4.0p37, before 2.3.0p51
Timeline
- 2026-09-21: disclosed: Public vulnerability disclosure