Vulnerability Description
Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/louislam/uptime-kuma/commit/7a9191761dbef6551c2a0aa6eed5f693b
- https://github.com/louislam/uptime-kuma/issues/5574
- https://github.com/louislam/uptime-kuma/pull/5573
FAQ
What is CVE-2025-26042?
CVE-2025-26042 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in th...
How severe is CVE-2025-26042?
CVE-2025-26042 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-26042?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.