CVE-2026-61551

NameCVE-2026-61551
DescriptionIcinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticated network clients through the Icinga 2 service on TCP port 5665, allowing a remote attacker to crash the process, while possible code execution has not been demonstrated. This issue is fixed in versions 2.14.9, 2.15.4, and 2.16.2.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6426-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
icinga2 (PTS)bookworm2.13.6-2+deb12u2vulnerable
trixie2.14.6-1vulnerable
trixie (security)2.14.6-1+deb13u1fixed
forky, sid2.16.5-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
icinga2sourcetrixie2.14.6-1+deb13u1DSA-6426-1
icinga2source(unstable)2.16.2-1

Notes

https://github.com/Icinga/icinga2/security/advisories/GHSA-wh38-wg57-5w7g
https://icinga.com/blog/icinga2-security-release-v2-16-2/
Fixed by: https://github.com/Icinga/icinga2/commit/ed163a8aa9d296820dd2ad14c47bf3f6a3fcce7d (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/b80132db87f0ead29d9061cf63d38ff69d92a616 (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/5ff0e61ad85cac5554b9560a4cee328512890e07 (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/547b55031a531c5579a966af8d7bc3675a7b1633 (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/dfda80415d41dabd0b04a350f1e7d2424b63fabd (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/77effd5bbbbf4e4b376b8a642ba5869ddd0bd416 (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/5288e833419d339c49c9f4f53ea41a008ae6c771 (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/f5b02b4885ff075b1ae5f8c0896878491fce1e10 (v2.16.2)
Fixed by: https://github.com/Icinga/icinga2/commit/391504eaa9ed9aee81f84008c57ec821974b74ee (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/6382675448bd28ca798e5d55d9a2306ad55ae509 (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/5bf588369d90d72184da526528d8783ea6bf8e08 (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/011c831632ed34c1f4ae33c3c9a72945b5e340c4 (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/2d3277799cf16b7546156f1b8e8db0df2604a14f (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/69093a8ae0f09bbef8f589cbc67f131f167e5aa3 (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/221d3fa9a66c248bc478220e4a73e1be661dd449 (v2.14.9)
Fixed by: https://github.com/Icinga/icinga2/commit/e23a3eb42d791f27c1073b56769800fe12156425 (v2.14.9)

Search for package or bug name: Reporting problems