Impact
Bugsink is a self‑hosted error‑tracking service that, before version 2.2.2, stored every set of custom tags attached to incoming events. An attacker who knows a project’s DSN can submit an event with an excessively large tag set. Because Bugsink’s database employs a single‑writer architecture, the resulting burst of write operations blocks the ingestion pipeline and temporarily denies further event processing. This flaw exemplifies CWE‑400 Resource Exhaustion, as the uncontrolled number of tags leads to excessive writes. The flaw has no impact on data confidentiality or integrity and cannot be used to execute code; it affects only the availability of the instance that receives the event.
Affected Systems
Any deployment of Bugsink prior. The affected product is the Bugsink error‑tracking server; no specific vendor versions beyond the change are listed.
Risk and Exploitability
The CVSS score of 4.3 places the flaw in the medium range. The EPSS score is below 1%, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an external client that submits a large tag set via the Bugsink API to the project DSN, which requires legitimate authentication but does not require elevated privileges.
OpenCVE Enrichment
Github GHSA