Vulnerabilities in bugsink
10 resultsVexday analysis
BugSink registra 9 vulnerabilidades acumuladas, com 1 crítica (CVSS) e nenhuma sob ataque ativo até o momento, reduzindo o risco imediato. Contudo, 4 vulnerabilidades publicadas nos últimos 90 dias indicam atividade recente de descoberta, concentradas em falhas de autorização (CWE-639), o que demanda atenção em processos de controle de acesso do fornecedor.
CVE-2025-54433HIGHBugsink is vulnerable to Path Traversal attacks via event_id in ingestionEPSS 0.6%CVE-2025-64508HIGHBugsink vulnerable to unauthenticated remote DoS via crafted Brotli inputEPSS 0.5%CVE-2026-53954MEDIUMBugsink: DOS using large numbers of event tagsEPSS 0.3%CVE-2025-64509HIGHBugsink vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)EPSS 0.3%CVE-2026-40162HIGHBugsink affected by authenticated arbitrary file write in artifactbundle/assembleEPSS 0.3%CVE-2026-27614CRITICALBugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace renderingEPSS 0.3%CVE-2026-44502MEDIUMBugsink: SSRF bypass in `validate_webhook_url`EPSS 0.3%CVE-2026-47728MEDIUMBugsink: Project scoping missing in sourcemap and debug-file lookupEPSS 0.2%CVE-2026-47715LOWBugsink: Issue event views can show an event from another project if its UUID is knownEPSS 0.2%CVE-2026-47716LOWBugsink: Issue bulk actions can affect another project’s issue if its UUID is knownEPSS 0.1%