Airbrake is an error tracking and monitoring service with a focused product footprint centered on its core platform and Ruby integration, exposing a limited attack surface. The durable signal among disclosures reflects information-exposure vulnerabilities, consistent with the sensitive nature of application diagnostics and error logs that such platforms handle. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Airbrake over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16060CRITICAL The Airbrake Ruby notifier 4.2.3 for Airbrake mishandles the blacklist_keys configuration option and consequently may disclose passwords to unauthorized actors. This is fixed in 4. | Sep 6, 2019 | 9.8 | 31 | NO | NO |
CVE-2016-10530MEDIUM The airbrake module 0.3.8 and earlier defaults to sending environment variables over HTTP. Environment variables can often times contain secret keys and other sensitive values. A m | May 31, 2018 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Airbrake.
Media articles that mention a CVE ID that affects a product developed by Airbrake — matched by CVE ID, not by vendor name.