VulnSea

bugsink has 9 CVEs on record between 2025 and 2026. Disclosures have slowed: 1 in the last 90 days after 5 in the 90 before. The busiest recent month was June 2026 with 3. The median CVSS is 4.3 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
4.3
Publish → KEV
Last 90 days
1 prev 5

Weakness classes

Products

  • bugsink 9
9
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

bugsink vulnerabilities

CVEs affecting bugsink, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-53954Medium· 4.3
1w ago

Bugsink is a self-hosted error tracking tool

Bugsink is a self-hosted error tracking tool. Prior to version 2.2.2, Bugsink stores every set of custom tags supplied with an incoming event, allowing a caller with a valid project DSN to submit an unusually large tag set and force exce…

Sunlitbugsink · bugsinkEPSS 0.32%via NVD
CVE-2026-47715Low· 3.1
3mo ago

Bugsink: Issue event views can show an event from another project if its UUID is known

Bugsink: Issue event views can show an event from another project if its UUID is known

Sunlitbugsink · bugsinkEPSS 0.15%via OSV
CVE-2026-47716Low· 3.1
3mo ago

Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known

Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known

Sunlitbugsink · bugsinkEPSS 0.15%via OSV
CVE-2026-47728Medium· 4.3
3mo ago

Bugsink: Project scoping missing in sourcemap and debug-file lookup

Bugsink: Project scoping missing in sourcemap and debug-file lookup

Sunlitbugsink · bugsinkEPSS 0.18%via OSV
CVE-2026-44502Medium· 4.3
4mo ago

Bunsink has an SSRF bypass in `validate_webhook_url`

Bunsink has an SSRF bypass in `validate_webhook_url`

Sunlitbugsink · bugsinkEPSS 0.29%via OSV
CVE-2026-40162High· 7.1
5mo ago

Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble

Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble

Twilightbugsink · bugsinkEPSS 0.30%via OSV
CVE-2025-64509High· 7.5
10mo ago

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input (via CPU)

Twilightbugsink · bugsinkEPSS 0.32%via OSV
CVE-2025-64508High· 7.5
10mo ago

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

Bugsink is vulnerable to unauthenticated remote DoS via crafted Brotli input

Twilightbugsink · bugsinkEPSS 0.47%via OSV
CVE-2025-54433High
1y ago

Bugsink path traversal via event_id in ingestion

Bugsink path traversal via event_id in ingestion

Twilightbugsink · bugsinkEPSS 0.56%via OSV
bugsink vulnerabilities (CVEs) · VulnSea