CVE-2026-77021: Checkmk GmbH Checkmk
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (EOL) allows an attacker who controls a host registered for push mode to exhaust the memory of the agent receiver by sending a small zlib compressed payload that decompresses to an arbitrary size.
Affected products
- Checkmk GmbH Checkmk: from 2.5.0, before 2.5.0p14 (fixed in 2.5.0p14); from 2.4.0, before 2.4.0p37 (fixed in 2.4.0p37); from 2.3.0, before 2.3.0p51 (fixed in 2.3.0p51); version 2.2.0 only
Published 2026-09-21. Last modified 2026-09-21.