bugsink
PyPI4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting bugsinkpage 1 of 1
- CVE-2025-54433HIGHCVSS 7.2EG 0.0✓ Fixed in 1.4.32025-07-30
vulnerable: 0.0.1 ... 1.4.2 (20 versions)
Bugsink is a self-hosted error tracking service. In versions 1.4.2 and below, 1.5.0 through 1.5.4, 1.6.0 through 1.6.3, and 1.7.0 through 1.7.3, ingestion paths construct file locations directly from untrusted event_id input without valid…
- CVE-2025-64508HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.52025-11-10
vulnerable: 0.0.1 ... 2.0.4 (45 versions)
Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli streams, such as many zeros) can be sent to the server. Since the server will attempt to decompress these streams before app…
- CVE-2025-64509HIGHCVSS 7.5EG 7.5✓ Fixed in 2.0.62025-11-10
vulnerable: 0.0.1 ... 2.0.5 (46 versions)
Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope can cause Bugsink to spend excessive CPU time in decompression, leading to denial of service. This can be done if the …
- CVE-2026-40162HIGHCVSS 7.1EG 7.1✓ Fixed in 2.1.12026-04-10
vulnerable: 2.1.0
Bugsink is a self-hosted error tracking tool. In 2.1.0, an authenticated file write vulnerability was identified in Bugsink 2.1.0 in the artifact bundle assembly flow. A user with a valid authentication token could cause the application to…
Check whether bugsink is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for bugsink CVEs against the assets you own.
Start Free Scan →