icinga
Latest CVEs
The 15 most recently published vulnerabilities affecting icinga.
- CVE-2026-61552Icinga 2 DSL Injection via Unescaped Import Template Name7.2
- CVE-2026-61551Icinga 2: Stack overflow via deeply nested JSON objects8.6
- CVE-2026-61550Icinga 2: Improper access control for JSON-RPC update certificate messages9.8
- CVE-2026-42224ipl/web is vulnerable to reflected XSS by malformed search requests7.6
- CVE-2026-24414Icinga for Windows certificate can have too-open permissions
- CVE-2026-24413Icinga has insecure permission of %ProgramData%\icinga2\var on Windows5.5
- CVE-2025-61909Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user4.4
- CVE-2025-61908Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference6.5
- CVE-2025-61907Icinga 2 API users could access restricted values in filter expressions6.5
- CVE-2025-61789Icinga DB Web hidden/protected custom variables are prone to filter enumeration5.3
- CVE-2025-53840Icinga DB Web Exposure of Sensitive Information to an Unauthorized Actor vulnerability2.4
- CVE-2025-48057Icinga 2 certificate renewal might incorrectly renew an invalid certificate9.8
- CVE-2025-30164Icinga Web 2 has open redirect on login page4.1
- CVE-2025-27609Icinga Web 2 Vulnerable to Reflected XSS5.4
- CVE-2025-27406Icinga Reporting Stored XSS leads to SSRF7.6