Known Vulnerabilities for Netdata by My-netdata
Listed below are 4 of the newest known vulnerabilities associated with "Netdata" by "My-netdata".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-71385 json | Netdata before 2.3.1 reflects the user-supplied love query parameter of the api/v2/ilove.svg and api/v3/ilove.svg endpoints v... | Not Provided | 2026-07-02 | 2026-07-14 |
| CVE-2018-18839 json | ** DISPUTED ** An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vend... | 5.3 - MEDIUM | 2019-06-18 | 2023-11-07 |
| CVE-2018-18838 json | An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter to a... | 7.5 - HIGH | 2019-06-18 | 2020-08-24 |
| CVE-2018-18837 json | An issue was discovered in Netdata 1.10.0. HTTP Header Injection exists via the api/v1/data filename parameter because of web... | 6.1 - MEDIUM | 2019-06-18 | 2019-06-19 |
| CVE-2018-18836 json | An issue was discovered in Netdata 1.10.0. JSON injection exists via the api/v1/data tqx parameter because of web_client_api_... | 6.5 - MEDIUM | 2019-06-18 | 2020-08-24 |