CVE-2025-49643: Zabbix Frontend

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

Affected products

  • Zabbix Frontend: from 6.0.0, before 6.0.42 (fixed in 6.0.42); from 7.0.0, before 7.0.19 (fixed in 7.0.19); from 7.2.0, before 7.2.13 (fixed in 7.2.13); from 7.4.0, before 7.4.3 (fixed in 7.4.3)

Published 2025-12-01. Last modified 2026-09-26.