CVE-2026-23935: Use-after-free read in script item/preprocessing HttpRequest body
A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading to potential confidentiality loss.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An authenticated Zabbix administrator is required to trigger the issue, so exposure is limited to environments where administrator access can be obtained or abused.
What is the likely impact of exploitation?
Successful exploitation can cause out-of-bounds memory disclosure, creating a potential confidentiality impact. The provided information does not establish that code execution, data modification, or service disruption is possible.
What configurations should be reviewed for exposure?
The issue is associated with script items or preprocessing that use JavaScript HttpRequest logic. Review administrator-created or administrator-accessible configurations using those features when assessing exposure.