top of page
perceptive_background_267k.jpg

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.t…

Published:

6 maart 2026 om 23:00:00

Alert date:

7 maart 2026 om 17:02:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization

UptimeFlare, a serverless uptime monitoring solution powered by Cloudflare Workers, had a vulnerability where sensitive server-only configuration data was exposed to client-side JavaScript bundles. The issue occurred because the configuration file exported both safe client data (pageConfig) and sensitive server data (workerConfig) from the same module. A client-side component incorrectly imported and used the server-only workerConfig, causing the entire sensitive configuration object to be included in JavaScript bundles served to all visitors. This exposed sensitive data that should have remained server-side only. The vulnerability was patched in commit 377a596.

Technical details

Mitigation steps:

Affected products:

UptimeFlare

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page