CVE-2023-22496 is a critical command injection vulnerability affecting Netdata agents, an open-source infrastructure monitoring tool. An unauthenticated attacker can execute arbitrary commands on a targeted Netdata agent by crafting a malicious registry_hostname within a streaming connection, leading to complete compromise of the affected system. With a CVSS score of 9.8 (Critical), this vulnerability has a low attack complexity and no user interaction required, allowing for high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code, Netdata has released fixes in agent v1.37 (stable) and v1.36.0-409 (nightly), and disabling streaming or restricting port access are recommended mitigations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.37.0CPE matchmatch criteria | cpe:2.3:a:netdata:netdata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Netdata Command Injection (CVE-2023-22496)
Mar 22, 2026Netdata Command Injection (CVE-2023-22496)
Mar 22, 2026Netdata Command Injection (CVE-2023-22496)
Mar 22, 2026Netdata Command Injection (CVE-2023-22496)
Mar 22, 2026