A Zabbix adminitrator can inject arbitrary SQL during the autoremoval of hosts by inserting malicious SQL in the 'Visible name' field.
[
{
"id": "CVE-2025-27240-54275493",
"signature_type": "Line",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
},
"source": "https://github.com/zabbix/zabbix/commit/ed6767dbdb3076660efe09dc69f22781fa9c9c0a",
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"115154101360858030922981434055701150851",
"195570750560698842948592063162645571807",
"229777919597073440585547007016699420692",
"310281707359805902864494292389069723081",
"49944654822291915530385878933710200727",
"285971086933706543778601192121026144741"
]
}
},
{
"id": "CVE-2025-27240-efef764d",
"signature_type": "Line",
"target": {
"file": "src/zabbix_java/src/com/zabbix/gateway/GeneralInformation.java"
},
"source": "https://github.com/zabbix/zabbix/commit/f383737f1083e25756c6afaaa8abff05ad11eb50",
"deprecated": false,
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"158703392381671019955663987886552441761",
"260539109617570610531885982419177346223",
"24620959945945567121836211561936761519",
"167792423538235293008428595269249306508",
"192204268449565753401476537568276663620",
"222572340168714685842508309588394178632"
]
}
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-27240.json"