oneuptime vulnerabilities
CVEs whose affected-version data names the oneuptime package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-35053Critical· 9.8OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, the Worker service's ManualAPI exposes workflow execution endpoints (GET /workflow/manual/run/:workflowId and POST /workflow/manual/run/:workflo…
CVE-2026-34840High· 8.1OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, OneUptime's SAML SSO implementation (App/FeatureSet/Identity/Utils/SSO.ts) has decoupled signature verification and identity extraction. isSigna…
CVE-2026-34759High· 8.1OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, multiple notification API endpoints are registered without authentication middleware, while sibling endpoints in the same codebase correctly use…
CVE-2026-34758Critical· 9.1OneUptime is an open-source monitoring and observability platform
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.42, unauthenticated access to Notification test and Phone Number management endpoints allows SMS/Call/Email/WhatsApp abuse and phone number purchase…