MEDIUM
Frontend DoS vulnerability due to asymmetric resource consumption
Published Dec 1, 2025
6.0
MEDIUMCVSS 4.0
EPSS 0.34%
Description
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Affected products
-
- Version 6.0.0StatusaffectedConstraints<=6.0.41
- Version 7.0.0StatusaffectedConstraints<=7.0.18
- Version 7.2.0StatusaffectedConstraints<=7.2.12
- Version 7.4.0StatusaffectedConstraints<=7.4.2
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Update the affected components to their respective fixed versions.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199985 Advisory
- https://support.zabbix.com/browse/ZBX-27284 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199985 | Advisory | |
| https://support.zabbix.com/browse/ZBX-27284 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Reserved Jun 9, 2025
Link CVE-2025-49643
CISA Vulnrichment
Updated Dec 1, 2025
ENISA EUVD
EUVD-2025-199985 Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Exploited since n/a
Link EUVD-2025-199985