PatchSiren

OneUptime CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OneUptime CVE published 2026-08-26

CVE-2026-80350

CVE-2026-80350 is a high-severity vulnerability in OneUptime's webhook target check, allowing an authenticated project member to configure a webhook that directs the server at loopback services, private network ranges, and link-local metadata endpoints. The vulnerability exists because the webhook delivery path does not properly validate IPv4-mapped IPv6 addresses, which can bypass the SSRF protection mec [truncated]

CRITICAL OneUptime CVE published 2026-05-27

CVE-2026-45102

OneUptime, an open-source monitoring and observability platform, contains a critical sandbox escape vulnerability in versions prior to 10.0.98. The platform uses Node.js's `vm` module as an isolation primitive for executing untrusted code. However, the `vm` module was not designed for secure isolation and can be escaped through manipulation of error objects and infinite recursion techniques. Successful ex [truncated]