Junglewise Threat Intelligence

CVE-2026-83600: Netdata denial of service via oversized CHART SLOT value

CVE-2026-83600 · Severity: medium · CVSS 6.5 · Published 2026-09-22

Technologies: Netdata. Vendors: Netdata.

Executive brief

Netdata is an open-source monitoring and observability platform used for real-time system metrics collection. An authenticated child agent or plugin can send a malformed CHART SLOT value that causes the parent Netdata agent to attempt allocating approximately 16 GB of memory, triggering an allocation failure that crashes the parent process. This disables centralized monitoring across an entire infrastructure while stream connectivity persists, allowing repeated denial of service attacks.

Technical details

The vulnerability exists in pluginsd_rrdset_cache_put_to_slot() within src/plugins.d/pluginsd_internals.h, where oversized CHART SLOT values from authenticated streams are not validated before being passed to reallocz(), causing excessive memory allocation attempts. An authenticated attacker with stream access can repeatedly trigger parent-agent crashes by sending crafted slot values exceeding sensible bounds. The fix (version 2.10.4 and nightly build 2.10.0-782-nightly) implements PLUGINSD_CHART_SLOT_MAX bounds checking to reject invalid slot values.

Affected products

  • Netdata Netdata prior to 2.10.4

Timeline

  • 2026-09-22: disclosed: CVE-2026-83600 published
  • 2026-06-08: patched: Fix committed (2.10.4 and nightly 2.10.0-782-nightly)

References

Related threats