Executive brief
Uptime Kuma is an open-source server monitoring tool that displays application availability and performance metrics via embeddable status badges. An unauthenticated attacker can query a specific API endpoint to extract average ping times for monitors that should be private, revealing the existence and response characteristics of internal services without authorization.
Technical details
The GET /api/badge/:id/ping/:duration endpoint in server/routers/api-router.js fails to validate that the requested monitor belongs to a public status page, unlike five other badge endpoints which correctly enforce an AND public = 1 check in their SQL queries. The vulnerable endpoint directly calls UptimeCalculator.getUptimeCalculator() with an attacker-supplied monitor ID without authorization verification. Any unauthenticated user on the network can enumerate monitor IDs and extract average response time data, allowing reconnaissance of internal monitored systems. The vulnerability was introduced in version 2.0.0 and patched in version 2.2.0 by adding the same public monitor authorization check used by other badge endpoints.
Affected products
- Uptime Kuma Uptime Kuma 2.0.0 to 2.1.3
Timeline
- 2026-03-12: disclosed
- 2026-03-12: patched: Fixed in version 2.2.0