bugsink
- Total products in the ecosystem
- 1
- Total vulnerabilities (90 days)
- 1
en
Verify to analyze this security profile
As of 09/19/2026, bugsink recorded 1 security vulnerabilities in the last 90 days across 1 products, including 0 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, bugsink had the most security vulnerabilities in the bugsink ecosystem, with 1 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-53954Bugsink: DOS using large numbers of event tags | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published09/15/2026 | SeverityMedium |
CVE-2026-47716Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published05/26/2026 | SeverityLow |
CVE-2026-47715Bugsink: Issue event views can show an event from another project if its UUID is known | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published05/26/2026 | SeverityLow |
CVE-2026-47728Bugsink: Project scoping missing in sourcemap and debug-file lookup | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published05/26/2026 | SeverityMedium |
CVE-2026-44502Bugsink: SSRF bypass in `validate_webhook_url` | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published05/26/2026 | SeverityMedium |
CVE-2026-40162Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published04/10/2026 | SeverityHigh |
CVE-2026-27614Bugsink is vulnerable to Stored XSS via Pygments fallback in stacktrace rendering | Exploitation statusPublic exploit | FixNot confirmed | Affected productbugsink | Published02/25/2026 | SeverityCritical |
CVE-2025-64509Bugsink vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU) | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published11/10/2025 | SeverityHigh |
CVE-2025-64508Bugsink vulnerable to unauthenticated remote DoS via crafted Brotli input | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published11/10/2025 | SeverityHigh |
CVE-2025-54433Bugsink is vulnerable to Path Traversal attacks via event_id in ingestion | Exploitation statusNot known exploited | FixYes | Affected productbugsink | Published07/30/2025 | SeverityHigh |