Security: roxy-wi/IncidentRelay
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Hard-coded default JWT signing key (dev-secret-key) in stock Docker → unauthenticated admin takeoverGHSA-qxgx-j99m-pv4v published
Sep 6, 2026 by Aidaho12Critical -
Telegram Action Handler Performs Alert Operations Without Team Authorization CheckGHSA-2464-jp5q-9h2c published
Sep 6, 2026 by Aidaho12Moderate -
Mattermost Action Secret Stored in Cleartext Inside Alert Post Integration ContextGHSA-x5hw-wg44-c483 published
Sep 6, 2026 by Aidaho12Moderate -
Silence Rule created_by Field Accepts Arbitrary User ID — Attribution SpoofingGHSA-75cr-gw4p-5xmm published
Sep 6, 2026 by Aidaho12Moderate -
Voice Provider Callback Secret Exposed in URL Path — Visible in Server Logs and CDRsGHSA-wv35-9m3x-7f65 published
Sep 6, 2026 by Aidaho12Moderate -
ReDoS via User-Controlled Regex in Alert Route MatchersGHSA-mr66-4rh5-4q66 published
Sep 6, 2026 by Aidaho12Moderate -
Client-Supplied user_id in Alert Ack/Resolve Allows Audit Trail ManipulationGHSA-39r7-j8wp-45vf published
Sep 6, 2026 by Aidaho12Moderate -
SSRF and Internal Error Disclosure via Notification Channel Webhook URLsGHSA-97xx-q4fw-m58g published
Sep 6, 2026 by Aidaho12High -
No Brute-Force Protection on Login Endpoint Allows Unlimited Password GuessingGHSA-gx2m-c4f4-jcr5 published
Sep 6, 2026 by Aidaho12High -
Notification Channel Credentials Exposed in Full via API ResponsesGHSA-fff8-vr33-7wcj published
Sep 6, 2026 by Aidaho12High
Learn more about advisories related to roxy-wi/IncidentRelay in the GitHub Advisory Database