<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Kuma</title>
  <link>https://cvedaily.com/pages/tags/kuma.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/kuma.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Kuma</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:41 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-45021 – Kuma is a modern Envoy-based service mesh that can run on every cloud across bot...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45021</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45021</guid>
    <pubDate>Thu, 28 May 2026 18:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-45021</strong></p>
  <p>Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.25, 2.9.15, 2.11.13, 2.12.10, and 2.13.5, the default kuma-cp config leaks the admin bootstrap token and signing keys to any webpage the operator visits while the control plane is reachable from their browser. CorsAllowedDomains: [".*"] reflects any Origin, and LocalhostIsAdmin: true…</p>
  <p><strong>CVSS:</strong> 5.1 · <strong>CWE:</strong> CWE-346</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45021">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33130 – Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33130</guid>
    <pubDate>Fri, 20 Mar 2026 10:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33130</strong></p>
  <p>Uptime Kuma is an open source, self-hosted monitoring tool. In versions 1.23.0 through 2.2.0, the fix from GHSA-vffh-c9pq-4crh doesn't fully work to preventServer-side Template Injection (SSTI). The three mitigations added to the Liquid engine (root, relativeReference, dynamicPartials) only block quoted paths. If a project uses an unquoted absolute path, attackers can still read any file on the s…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-98</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32230 – Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32230</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32230</guid>
    <pubDate>Thu, 12 Mar 2026 19:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32230</strong></p>
  <p>Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify that the requested monitor belongs to a public group. All other badge endpoints check AND public = 1 in their SQL query before returning data. The ping endpoint skips this check entirely, allowing unauthenticated users to…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32230">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-26042 – Uptime Kuma &gt;== 1.23.0 has a ReDoS vulnerability, specifically when an administr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-26042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-26042</guid>
    <pubDate>Mon, 17 Mar 2025 19:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-26042</strong></p>
  <p>Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-1333</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-26042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-56331 – Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56331</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56331</guid>
    <pubDate>Fri, 20 Dec 2024 20:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-56331</strong></p>
  <p>Uptime Kuma is an open source, self-hosted monitoring tool. An **Improper URL Handling Vulnerability** allows an attacker to access sensitive local files on the server by exploiting the `file:///` protocol. This vulnerability is triggered via the **"real-browser"** request type, which takes a screenshot of the URL provided by the attacker. By supplying local file paths, such as `file:///etc/passw…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56331">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-36542 – Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-36542</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-36542</guid>
    <pubDate>Thu, 25 Jul 2024 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-36542</strong></p>
  <p>Insecure permissions in kuma v2.7.0 allows attackers to access sensitive data and escalate privileges by obtaining the service account's token.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-277</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-36542">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49805 – Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49805</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49805</guid>
    <pubDate>Mon, 11 Dec 2023 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49805</strong></p>
  <p>Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, the application uses WebSocket (with Socket.io), but it does not verify that the source of communication is valid. This allows third-party website to access the application on behalf of their client. When connecting to the server using Socket.IO, the server does not validate the `Origin` header leading to other si…</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-1385</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49805">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49804 – Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49804</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49804</guid>
    <pubDate>Mon, 11 Dec 2023 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49804</strong></p>
  <p>Uptime Kuma is an easy-to-use self-hosted monitoring tool. Prior to version 1.23.9, when a user changes their login password in Uptime Kuma, a previously logged-in user retains access without being logged out. This behavior persists consistently, even after system restarts or browser restarts. This vulnerability allows unauthorized access to user accounts, compromising the security of sensitive i…</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49804">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-49276 – Uptime Kuma is an open source self-hosted monitoring tool. In affected versions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49276</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49276</guid>
    <pubDate>Fri, 01 Dec 2023 22:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-49276</strong></p>
  <p>Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (XSS). Since the custom status interface can set an independent Google Analytics ID and the template has not been sanitized, there is an attribute injection vulnerability here, which can lead to XSS attacks. This vulnerab…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49276">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-44400 – Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-44400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-44400</guid>
    <pubDate>Mon, 09 Oct 2023 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-44400</strong></p>
  <p>Uptime Kuma is a self-hosted monitoring tool. Prior to version 1.23.3, attackers with access to a user's device can gain persistent account access. This is caused by missing verification of Session Tokens after password changes and/or elapsed inactivity periods. Version 1.23.3 has a patch for the issue.</p>
  <p><strong>CVSS:</strong> 6.7 · <strong>CWE:</strong> CWE-384</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-44400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36822 – Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36822</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36822</guid>
    <pubDate>Wed, 05 Jul 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36822</strong></p>
  <p>Uptime Kuma, a self-hosted monitoring tool, has a path traversal vulnerability in versions prior to 1.22.1. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in the web interface, but the corresponding API endpoints are still available after login. Before a plugin is downloaded, the plugin installation directory is check…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36822">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36821 – Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36821</guid>
    <pubDate>Wed, 05 Jul 2023 22:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36821</strong></p>
  <p>Uptime Kuma, a self-hosted monitoring tool, allows an authenticated attacker to install a maliciously crafted plugin in versions prior to 1.22.1, which may lead to remote code execution. Uptime Kuma allows authenticated users to install plugins from an official list of plugins. This feature is currently disabled in the web interface, but the corresponding API endpoints are still available after l…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26777 – Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26777</guid>
    <pubDate>Tue, 04 Apr 2023 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26777</strong></p>
  <p>Cross Site Scripting vulnerability found in : louislam Uptime Kuma v.1.19.6 and before allows a remote attacker to execute arbitrary commands via the description, title, footer, and incident creation parameter of the status_page.js endpoint.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25811 – Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25811</guid>
    <pubDate>Tue, 21 Feb 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25811</strong></p>
  <p>Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma `name` parameter allows a persistent XSS attack. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-25810 – Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Up...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-25810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-25810</guid>
    <pubDate>Tue, 21 Feb 2023 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-25810</strong></p>
  <p>Uptime Kuma is a self-hosted monitoring tool. In versions prior to 1.20.0 the Uptime Kuma status page allows a persistent XSS attack. Users are advised to upgrade. There are no known workarounds for this vulnerability.</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-25810">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
