CVE-2026-59783
Received Received - Intake

NULL Byte Input Crash in Zabbix Server/Proxy with MySQL/MariaDB

Vulnerability report for CVE-2026-59783, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Zabbix

Description

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy on certain NULL byte input leading to potential loss of availability. This only affects deployments where MySQL/MariaDB database is used as the Zabbix database.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
Zabbix Zabbix 7.0.0
Zabbix Zabbix 7.4.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Zabbix Server/Proxy has a vulnerability where binary items can crash the Server/Proxy when certain NULL byte inputs are received. This causes a loss of availability and only affects systems using MySQL or MariaDB as the Zabbix database.

Detection Guidance

This vulnerability affects Zabbix Server/Proxy with MySQL/MariaDB databases when NULL byte input crashes the system. Detection requires checking Zabbix logs for crashes or unusual binary item processing failures. Monitor for Server/Proxy process restarts or database connection errors.

Impact Analysis

This vulnerability can lead to unexpected crashes of the Zabbix Server or Proxy, disrupting monitoring services and causing downtime. If you rely on Zabbix for system monitoring, this could affect your ability to track and manage infrastructure.

Compliance Impact

This vulnerability primarily impacts availability by crashing the Zabbix Server/Proxy on NULL byte input in binary items. For GDPR, it could lead to service disruptions affecting data processing operations. For HIPAA, downtime may impact monitoring of critical systems handling protected health information.

Mitigation Strategies

Apply the latest Zabbix Server/Proxy patch or update to address the NULL byte input handling issue. If using MySQL/MariaDB, verify the database configuration and ensure proper input validation is enforced at the application level.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59783. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart