Stack-based buffer overflow in Icinga - CVE-2026-61551
Published: June 29, 2026 / Updated: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in the JSON parser when processing deeply nested JSON objects. A remote attacker can send specially crafted JSON input to cause a denial of service.
The affected code is reachable by unauthenticated clients over the network. The possibility of code execution cannot be ruled out, but it has not been demonstrated.
Affected software
Debian Linux
icinga2 (Debian package)
How to mitigate CVE-2026-61551
icinga2 (Debian package) - update to 2.14.6-1+deb13u1