CVE-2026-61551

Source
https://cve.org/CVERecord?id=CVE-2026-61551
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61551.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-61551
Aliases
  • GHSA-wh38-wg57-5w7g
Downstream
Published
2026-09-18T17:23:11Z
Modified
2026-09-19T03:47:23Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H CVSS Calculator
Summary
Icinga 2: Stack overflow via deeply nested JSON objects
Details

Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticated network clients through the Icinga 2 service on TCP port 5665, allowing a remote attacker to crash the process, while possible code execution has not been demonstrated. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-674"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61551.json"
}
References

Affected packages

Git / github.com/icinga/icinga2

Affected ranges

Type
GIT
Repo
https://github.com/icinga/icinga2
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.14.9"
        },
        {
            "introduced": "2.15.0"
        },
        {
            "fixed": "2.15.4"
        },
        {
            "introduced": "2.16.0"
        },
        {
            "fixed": "2.16.2"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v0.*
v0.0.1
v0.0.10
v0.0.11
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v2.*
v2.0.0
v2.0.0-beta1
v2.0.0-beta2
v2.0.1
v2.0.2
v2.1.0
v2.1.1
v2.10.0
v2.10.1
v2.11.0
v2.11.0-rc1
v2.12.0
v2.12.0-rc1
v2.13.0
v2.14.0
v2.14.1
v2.14.2
v2.14.4
v2.14.5
v2.15.0
v2.15.3
v2.16.0
v2.16.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-61551.json"