Uptime Kuma是Louis Lam个人开发者的一个易于使用的自托管监控工具。 Uptime Kuma 2.0.0至2.1.3版本存在安全漏洞,该漏洞源于未验证请求的监视器是否属于公共组,可能导致未经验证的用户提取私有监视器的平均ping或响应时间数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| louislam | uptime-kuma | >= 2.0.0, < 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Uptime-Kuma before v1.23.0 is vulnerable to an information disclosure issue due to missing authorization on the /api/badge/1/ping/24 endpoint. An unauthenticated attacker can access this endpoint to leak ping statistics, such as average ping and ping history, for existing monitors without needing access to the protected status page. This can lead to unintended exposure of internal monitoring data. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-32230.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet