CVE-2025-26042

CVSS 3.1 Score 6 of 10 (medium)

Details

Published Mar 17, 2025
Updated: Mar 19, 2025
CWE ID 1333

Summary

CVE-2025-26042 is a newly disclosed vulnerability affecting Uptime Kuma versions greater than or equal to 1.23.0. This issue involves a ReDoS (Regular Expression Denial of Service) vulnerability, which can be triggered when an administrator creates a notification through the web service. When a specific malicious string is provided, it causes catastrophic backtracking in the regular expression, leading to a ReDoS attack. This vulnerability can result in denial of service conditions and should be addressed promptly by updating to a patched version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share