Description
The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the affected components to their respective fixed versions.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28193 |
|
History
Mon, 05 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The JavaScript preprocessing (Duktape) engine on Zabbix server has a vulnerability where a limited administrator is able to read raw heap data potentially resulting in leaked data from other running preprocessors not available to said administrator. | |
| Title | JavaScript preprocessing memory disclosure | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-10-05T10:27:34.672Z
Reserved: 2026-07-07T08:30:49.859Z
Link: CVE-2026-59782
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-125
Out-of-bounds Read