Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2026-30829
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Checkmate: Unauthenticated Access to Unpublished Status Page
Source: NVD (National Vulnerability Database)
Vulnerability Description
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. Prior to version 3.4.0, an unauthenticated information disclosure vulnerability exists in the GET /api/v1/status-page/:url endpoint. The endpoint does not enforce authentication or verify whether a status page is published before returning full status page details. As a result, unpublished status pages and their associated internal data are accessible to any unauthenticated user via direct API requests. This issue has been patched in version 3.4.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
信息暴露
Source: NVD (National Vulnerability Database)
Vulnerability Title
Checkmate 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Checkmate是BlueWave开源的一个开源、自托管的工具,旨在通过精美的可视化实时跟踪和监控服务器硬件、正常运行时间、响应时间和事件。 Checkmate 3.4.0之前版本存在信息泄露漏洞,该漏洞源于GET /api/v1/status-page/:url端点未强制执行身份验证或验证状态页是否已发布,可能导致未经验证的用户访问未发布状态页及其内部数据。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
bluewave-labsCheckmate < 3.4.0 -
II. Public POCs for CVE-2026-30829
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2026-30829
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2026-30829

No comments yet


Leave a comment