CVE-2026-83599

Netdata is an open source observability tool. Prior to 2.11.0, Netdata's unauthenticated WebSocket server negotiates permessage-deflate before authentication, and src/web/websocket/websocket-compression.c allows websocket_client_decompress_message() to grow decompressed output toward WS_MAX_DECOMPRESSED_SIZE without enforcing a compressed-to-decompressed ratio. Small highly compressed frames can therefore cause large server-side allocations, and repeated concurrent connections can exhaust memory and terminate monitoring. This vulnerability is fixed in 2.11.0.

  • Published Sep 22, 2026
  • CVSS 7.5 high
  • 0.7% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-83599 at the National Vulnerability Database