VYPR

Oneuptime

by Oneuptime

Source repositories

CVEs (25)

  • CVE-2026-33143HigMar 20, 2026
    risk 0.42cvss 7.5epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.34, the WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature,…

  • CVE-2026-32308HigMar 13, 2026
    risk 0.42cvss 7.6epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.23, the Markdown viewer component renders Mermaid diagrams with securityLevel: "loose" and injects the SVG output via innerHTML. This configuration explicitly allows interactive event bindings in…

  • CVE-2026-80350HigAug 26, 2026
    risk 0.39cvss 7.1epss 0.00

    OneUptime's webhook target check rejects private and loopback addresses given in IPv4 form and a small set of IPv6 forms, but has no case for the IPv4-mapped IPv6 range. The webhook delivery path calls SSRFProtection.validateWebhookTargetIsSafe, and the host-literal screening…

  • CVE-2026-32598MedMar 13, 2026
    risk 0.35cvss 6.5epss 0.00

    OneUptime is a solution for monitoring and managing online services. Prior to 10.0.24, the password reset flow logs the complete password reset URL — containing the plaintext reset token — at INFO log level, which is enabled by default in production. Anyone with access to…

  • CVE-2026-30959MedMar 10, 2026
    risk 0.33cvss 5.0epss 0.00

    OneUptime is a solution for monitoring and managing online services. The resend-verification-code endpoint allows any authenticated user to trigger a verification code resend for any UserWhatsApp record by ID. Ownership is not validated (unlike the verify endpoint). This affects…

Page 2 of 2