Netdata is a single-product open-source monitoring and observability platform that offers agent-based real-time metrics collection and visualization across distributed systems. Its vulnerability profile centers on the core Netdata agent and recurs through web-tier and access-control weakness classes, including exposure of resources to unintended spheres, improper authentication, input validation flaws, cross-site scripting, and command injection—patterns typical of a network-facing daemon with authentication and API components. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netdata over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22496CRITICAL Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary | Jan 14, 2023 | 9.8 | 49 | NO | NO |
CVE-2025-71385MEDIUM Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints verbatim into the generated SVG document (into a text el | Jul 2, 2026 | 6.1 | 28 | NO | NO |
CVE-2023-22497CRITICAL Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. Each Netdata Agent has an automatically generated MACHINE GUID. It is generated when t | Jan 14, 2023 | 9.1 | 28 | NO | NO |
CVE-2019-9834MEDIUM The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an imported snapshot, aka HTML Injection. Successful exploitation wi | Mar 15, 2019 | 6.1 | 26 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netdata.
Media articles that mention a CVE ID that affects a product developed by Netdata — matched by CVE ID, not by vendor name.