Input validation error in Zabbix - CVE-2026-59783
Published: October 5, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper handling of null byte input in Zabbix Server and Proxy binary items when processing malicious data sent through trapper access. A remote user can send malicious binary-item data containing null bytes to cause a denial of service.
Only deployments using MySQL or MariaDB as the Zabbix database are affected.
Affected software
Fedora
zabbix7.0
How to mitigate CVE-2026-59783
zabbix7.0 - addressed in versions 7.0.31-1.el8, 7.0.31-1.el9, 7.0.31-1.el10_2, 7.0.31-1.el10_3, 7.0.31-1.el10_4