


Perceptive Security
SOC/SIEM Consultancy

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.t…
Published:
6 maart 2026 om 23:00:00
Alert date:
7 maart 2026 om 17:02:49
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization
UptimeFlare, a serverless uptime monitoring solution powered by Cloudflare Workers, had a vulnerability where sensitive server-only configuration data was exposed to client-side JavaScript bundles. The issue occurred because the configuration file exported both safe client data (pageConfig) and sensitive server data (workerConfig) from the same module. A client-side component incorrectly imported and used the server-only workerConfig, causing the entire sensitive configuration object to be included in JavaScript bundles served to all visitors. This exposed sensitive data that should have remained server-side only. The vulnerability was patched in commit 377a596.
Technical details
Mitigation steps:
Affected products:
UptimeFlare
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-29779
https://github.com/lyc8503/UptimeFlare/commit/377a5963c66ba9a798abebfe8d80378b053435e9
https://github.com/lyc8503/UptimeFlare/issues/198
https://github.com/lyc8503/UptimeFlare/security/advisories/GHSA-36q9-v7p3-vj6v
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
