alpine · CVE-2025-49643

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2025-49643: 1 source package rows (zabbix); 35 state rows across 3 repos (3.22-community, 3.23-community, edge-community); fixed 20, open 15.

Description:

An authenticated Zabbix user (including Guest) is able to cause disproportionate CPU load on the webserver by sending specially crafted parameters to /imgstore.php, leading to potential denial of service.

cvelogic Threat Intelligence