Security: louislam/uptime-kuma
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Another Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File ReadGHSA-v832-4r73-wx5j published
Mar 16, 2026 by louislamModerate -
Missing Authorization Check on Ping Badge Endpoint Leaks Ping times of montors without needing to be on a status pageGHSA-c7hf-c5p5-5g6h published
Mar 11, 2026 by louislamModerate -
RSS status feed does not set content type, leading to a Stored XSS in Public Status Page RSS Feed via CDATA escaped Monitor Name IF USING AN UNSECURE CLIENTGHSA-9fg7-wgm7-57fh published
Feb 8, 2026 by louislamLow -
Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File ReadGHSA-vffh-c9pq-4crh published
Oct 20, 2025 by louislamModerate -
Unauthenticated file read of files that begin with `index.`GHSA-5px6-fx2w-459r published
Jun 4, 2025 by louislamHigh -
GCP and selected cloud providers provide metadata endpoints to the local network which can be queried to extract sensitive information via authentificated accounts in uptime kumaGHSA-qjxc-h5jf-c7rj published
Oct 13, 2025 by louislamModerate -
Regular Expression in pushdeeer and whapi file Leads to ReDoS Vulnerability Due to Catastrophic BacktrackingGHSA-hx7h-9vf7-5xhg published
Mar 29, 2025 by louislamModerate -
Local File Inclusion (LFI) via Improper URL Handling in `Real-Browser` monitorGHSA-2qgm-m29m-cj2h published
Dec 20, 2024 by louislamModerate -
Enabling Authentication does not close all logged in socket connections immediatelyGHSA-23q2-5gf8-gjpp published
Apr 19, 2024 by louislamLow -
Changing Password does not close all logged in socket connections immediatelyGHSA-88j4-pcx8-q4q3 published
Dec 10, 2023 by louislamModerate