๐Ÿ” CVE Alert

CVE-2026-29779

HIGH 7.5

UptimeFlare: Montior config / Credentials in `workerConfig` exposed in client-side JavaScript bundle

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.ts exports both pageConfig (safe for client use) and workerConfig (server-only, contains sensitive data) from the same module. Due to pages/incidents.tsx importing and using workerConfig directly inside client-side component code, the entire workerConfig object was included in the client-side JavaScript bundle served to all visitors. This issue has been patched via commit 377a596.

CWE CWE-200
Vendor lyc8503
Product uptimeflare
Published Mar 7, 2026
Last Updated Mar 9, 2026
Stay Ahead of the Next One

Get instant alerts for lyc8503 uptimeflare

Be the first to know when new high vulnerabilities affecting lyc8503 uptimeflare are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

lyc8503 / UptimeFlare
< 377a5963c66ba9a798abebfe8d80378b053435e9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lyc8503/UptimeFlare/security/advisories/GHSA-36q9-v7p3-vj6v github.com: https://github.com/lyc8503/UptimeFlare/issues/198 github.com: https://github.com/lyc8503/UptimeFlare/commit/377a5963c66ba9a798abebfe8d80378b053435e9