Stack-based buffer overflow in Icinga - CVE-2026-61551

 

Stack-based buffer overflow in Icinga - CVE-2026-61551

Published: June 29, 2026 / Updated: September 22, 2026


Vulnerability identifier: #VU135838
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-61551
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to stack-based buffer overflow in the JSON parser when processing deeply nested JSON objects. A remote attacker can send specially crafted JSON input to cause a denial of service.

The affected code is reachable by unauthenticated clients over the network. The possibility of code execution cannot be ruled out, but it has not been demonstrated.


Affected software

Icinga
Debian Linux
icinga2 (Debian package)

How to mitigate CVE-2026-61551

Install security update from vendor's website.

Icinga - addressed in versions 2.14.9, 2.15.4, 2.16.2
icinga2 (Debian package) - update to 2.14.6-1+deb13u1

External References

Related Security Bulletins