Description
The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
Update the affected components and replace the deployed zabbix_trap_receiver.pl with the fixed version.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-28197 |
|
History
Mon, 05 Oct 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Perl SNMP trap receiver script shipped with Zabbix does not properly neutralize the ZBXTRAP record delimiter in trap content. This means someone able to send SNMP traps can inject a record targeting another host, resulting in a loss of integrity. | |
| Title | SNMP trap injection in zabbix_trap_receiver.pl | |
| Weaknesses | CWE-143 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Zabbix
Published:
Updated: 2026-10-05T10:29:20.302Z
Reserved: 2026-07-07T08:30:49.860Z
Link: CVE-2026-59787
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-143
Improper Neutralization of Record Delimiters