Icinga2
Icinga · 12 CVEs
Icinga 2 DSL Injection via Unescaped Import Template Name
Sep 18, 2026
Icinga 2: Stack overflow via deeply nested JSON objects
Sep 18, 2026
Icinga 2: Improper access control for JSON-RPC update certificate messages
Sep 18, 2026
Icinga has insecure permission of %ProgramData%\icinga2\var on Windows
Jan 29, 2026
Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user
Oct 16, 2025
Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference
Oct 16, 2025
Icinga 2 API users could access restricted values in filter expressions
Oct 16, 2025
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
May 27, 2025
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
Nov 12, 2024
Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer
Aug 19, 2021
Passwords used to access external services inadvertently exposed through API
Jul 15, 2021
Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) iden…
Jul 15, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-61552 | Icinga 2 DSL Injection via Unescaped Import Template Name | HIGH | 0.90% | Sep 18, 2026 |
| CVE-2026-61551 | Icinga 2: Stack overflow via deeply nested JSON objects | HIGH | 0.94% | Sep 18, 2026 |
| CVE-2026-61550 | Icinga 2: Improper access control for JSON-RPC update certificate messages | CRITICAL | 0.67% | Sep 18, 2026 |
| CVE-2026-24413 | Icinga has insecure permission of %ProgramData%\icinga2\var on Windows | MEDIUM | 0.08% | Jan 29, 2026 |
| CVE-2025-61909 | Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user | MEDIUM | 0.22% | Oct 16, 2025 |
| CVE-2025-61908 | Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference | HIGH | 0.54% | Oct 16, 2025 |
| CVE-2025-61907 | Icinga 2 API users could access restricted values in filter expressions | HIGH | 0.40% | Oct 16, 2025 |
| CVE-2025-48057 | Icinga 2 certificate renewal might incorrectly renew an invalid certificate | CRITICAL | 0.44% | May 27, 2025 |
| CVE-2024-49369 | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections | CRITICAL | 2.92% | Nov 12, 2024 |
| CVE-2021-37698 | Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer | HIGH | 1.38% | Aug 19, 2021 |
| CVE-2021-32743 | Passwords used to access external services inadvertently exposed through API | HIGH | 1.80% | Jul 15, 2021 |
| CVE-2021-32739 | Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities | HIGH | 1.14% | Jul 15, 2021 |
Showing 1 to 12 of 12 CVEs