Back

MEDIUM

Frontend DoS vulnerability due to asymmetric resource consumption

Published Dec 1, 2025

Description

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

Affected products

Remediation

Vendor solution

Update the affected components to their respective fixed versions.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Reserved Jun 9, 2025
CISA Vulnrichment
Updated Dec 1, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Zabbix
Published Dec 1, 2025
Updated Dec 1, 2025
Exploited since n/a
EUVD-2025-199985