CVE-2025-49643
published 2025-12-01CVE-2025-49643: An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to…
PriorityP434medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.30%
22.5th percentile
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:7.0.22+dfsg-1 (forky) | zabbix 1:7.0.22+dfsg-1 (forky) |
| zabbix | frontend | >= 6.0.0 < 6.0.42 | 6.0.42 |
| zabbix | frontend | >= 7.0.0 < 7.0.19 | 7.0.19 |
| zabbix | frontend | >= 7.2.0 < 7.2.13 | 7.2.13 |
| zabbix | frontend | >= 7.4.0 < 7.4.3 | 7.4.3 |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1~deb13u1 | 1:7.0.22+dfsg-1~deb13u1 |
| zabbix | zabbix | >= 0 < 1:7.0.22+dfsg-1 | 1:7.0.22+dfsg-1 |
| zabbix | zabbix | 6.0.0 – 6.0.41 | — |
| zabbix | zabbix | 7.0.0 – 7.0.18 | — |
| zabbix | zabbix | 7.2.0 – 7.2.12 | — |
| zabbix | zabbix | 7.4.0 – 7.4.2 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-49643: An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to
osv·2025-12-01·CVSS 6.0
CVE-2025-49643 [MEDIUM] CVE-2025-49643: An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
GHSA
GHSA-728r-qj99-48p2: An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to
ghsa_unreviewed·2025-12-01
CVE-2025-49643 [MEDIUM] CWE-405 GHSA-728r-qj99-48p2: An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Debian
CVE-2025-49643: zabbix - An authenticated Zabbix user (including Guest) is able to cause disproportionate...
vendor_debian·2025·CVSS 6.0
CVE-2025-49643 [MEDIUM] CVE-2025-49643: zabbix - An authenticated Zabbix user (including Guest) is able to cause disproportionate...
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:7.0.22+dfsg-1)
sid: resolved (fixed in 1:7.0.22+dfsg-1)
trixie: resolved (fixed in 1:7.0.22+dfsg-1~deb13u1)
No detection rules found.
No public exploits indexed.
2025-12-01
Published