CVE-2025-49643: Frontend DoS vulnerability due to asymmetric resource consumption
An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-49643?
CVE-2025-49643 has a severity rating indicating it can lead to a denial of service by causing excessive CPU load.
How do I fix CVE-2025-49643?
To fix CVE-2025-49643, update Zabbix to a version that addresses the vulnerability and limits the impact of specially crafted parameters.
Who is affected by CVE-2025-49643?
CVE-2025-49643 affects any authenticated Zabbix user, including guest accounts.
What are the potential impacts of CVE-2025-49643?
The potential impacts of CVE-2025-49643 include a denial of service resulting from increased CPU load on the webserver.
Where does CVE-2025-49643 occur in Zabbix?
CVE-2025-49643 occurs specifically when parameters are sent to the /imgstore.php endpoint in Zabbix.