CVE-2026-29779Disclosure(lyc8503 / uptimeflare)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lyc8503 uptimeflare systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.ts exports both pageConfig (safe for client use) and workerConfig (server-only, contains sensitive data) from the same module. Due to pages/incidents.tsx importing and using workerConfig directly inside client-side component code, the entire workerConfig object was included in the client-side JavaScript bundle served to all visitors. This issue has been patched via commit 377a596.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • uptimeflare

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-12); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
uptimeflare

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-07: 1Mentions · 2026-03-09: 1Mentions · 2026-03-12: 2Mentions · 2026-09-24: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 1Technical Details · 2026-09-24: 103-0703-0903-1209-24
Signal classification2 categories
Disclosure
360.0%
General
240.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-071
General1
2026-03-091
Disclosure1
2026-03-122
Disclosure1General1
2026-09-241
Disclosure1
Full discourse5 posts
  • Olajeedae Jr 🇳🇬@r007User
    Disclosure

    And it is not even theoretical. UptimeFlare shipped server-only creds inside a client-side JS bundle this year, anyone could pull the keys straight from the bundle. CVE-2026-29779. R2 credentials belong server-side. Your JS bundle is public. Those two things should never meet.

    Post summary

    The tweet announces CVE‑2026‑29779, describing how UptimeFlare exposed server‑only credentials in a publicly accessible client‑side JavaScript bundle, enabling key extraction.

    00031110
    1.4K followersView on X
  • Vivek | ThreatIntel@VivekIntel
    Disclosure

    CVE-2026-29779: UptimeFlare Misconfiguration Exposes Server-Side Secrets via Client Bundle A security flaw tracked as CVE-2026-29779 (CVSS 7.5) affects UptimeFlare, a serverless uptime monitoring and status-page platform built on Cloudflare Workers. The issue stems from improper separation of configuration objects during the build process. A server-side object (workerConfig) intended only for backend execution was inadvertently bundled into the public client-side JavaScript. As a result, any visitor loading the status page could potentially retrieve sensitive configuration data directly from the delivered script. Depending on deployment practices, exposed data may include: • API keys or service tokens • internal endpoints or network paths • backend service configuration • other environment-specific secrets used by the Worker runtime Although categorized as an information disclosure vulnerability, leaked configuration artifacts can significantly reduce attacker effort in reconnaissance and enable follow-on compromise of connected services. The issue has been addressed starting from commit 377a596, which properly separates client and server configuration during the build process. Organizations running UptimeFlare should: • update to the patched commit immediately • rotate any credentials previously stored in workerConfig • review publicly served JS bundles to ensure no sensitive configuration remains exposed Advisory: https://www.yazoul.net/advisory/cve/cve-2026-29779 #CyberSecurity #ThreatIntel #CVE #VulnerabilityManagement

    Post summary

    A disclosure of CVE-2026-29779 details an UptimeFlare misconfiguration that exposes sensitive configuration data via the client bundle; a patch is available and users are urged to update and rotate credentials.

    0100053
    193 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29779 UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377a596, configuration file uptime.config.ts expo… https://www.cve.org/CVERecord?id=CVE-2026-29779

    Post summary

    A brief note referencing CVE‑2026‑29779 and a commit ID, without any actionable details regarding proof‑of‑concepts, exploitation, or mitigation.

    00010116
    56.6K followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-29779 (CVSS:7.5, HIGH) is Analyzed. UptimeFlare is a serverless uptime monitoring & status page solution, powered by Cloudflare Workers. Prior to commit 377..https://nvd.nist.gov/vuln/detail/CVE-2026-29779 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The content merely states that CVE‑2026‑29779 has been analyzed with a CVSS score of 7.5, but provides no PoC, exploit, patch, or detailed technical information.

    0000028
    172 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 UptimeFlare, Sensitive Data Exposure, #CVE-2026-29779 (High) https://dailycve.com/uptimeflare-sensitive-data-exposure-cve-2026-29779-high/

    Post summary

    A brief announcement of CVE‑2026‑29779, a high‑severity sensitive data exposure issue in UptimeFlare, is provided along with a link to a dailycve article.

    0000026
    167 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applyc8503uptimeflare---

Explore more