Security: gotify/server
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Plugin Messages can lead to Denial-of-Service due to WebSocket stream module use-after-closeGHSA-78w7-2h8c-8252 published
Aug 27, 2026 by jmattheisModerate -
Insufficiently Protected Password Change endpoint in github.com/gotify/server/v2GHSA-3hcj-9m7p-wwm9 published
Jul 24, 2026 by jmattheisModerate -
Reflected XSS in Gotify's /docs via import of outdated Swagger UI (3.20.5)GHSA-3244-8mff-w398 published
Jan 10, 2023 by jmattheisModerate -
XSS vulnerability in the application image file uploadGHSA-xv6x-456v-24xh published
Dec 29, 2022 by jmattheisModerate