Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53954— Bugsink: DOS using large numbers of event tags

Quick assessment

Affected
bugsink bugsink
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Bugsink 是一款自托管的错误跟踪工具。在 2.2.2 版本之前,Bugsink 会保存随每个传入事件提交的所有自定义标签集合。这意味着,拥有有效项目 DSN 的调用者可以提交异常大量的标签集,从而强制系统执行过度的标签行写入操作。由于 Bugsink 采用单写入者数据库架构,这种高耗时的写入事务会延迟对其他事件的消化处理,导致短暂的摄取(ingestion)拒绝服务(Denial of Service)。 2.2.2 版本在存储前应用了可配置的 MAX_EVENT_TAGS 限制。该漏洞的影响仅限于接受该事件

CVSS 4.3 · Medium EPSS 0.06% · P18

Affected Version Matrix 1

VendorProduct Version RangeStatus
bugsink bugsink < 2.2.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53954

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Bugsink: DOS using large numbers of event tags
Source: CVE Program / CVE List V5
Vulnerability Description
Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force excessive tag-row writes. Because Bugsink uses a single-writer database architecture, the expensive write transaction delays digestion of other events and causes a temporary ingestion denial of service. Version 2.2.2 applies the configurable MAX_EVENT_TAGS limit before storage. The impact is limited to availability for an instance accepting the event and does not expose stored data, modify existing events, or allow code execution. This issue is fixed in version 2.2.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
bugsink bugsink < 2.2.2 -

II. Public POCs for CVE-2026-53954

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53954

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53954 (1)

Vendor Pages for CVE-2026-53954 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-53954

No comments yet


Leave a comment