Description
The WhatsApp POST webhook handler (/notification/whatsapp/webhook) processes incoming status update events without verifying the Meta/WhatsApp X-Hub-Signature-256 HMAC signature, allowing any unauthenticated attacker to send forged webhook payloads that manipulate notification delivery status records, suppress alerts, and corrupt audit trails.
Recommendation
Update the oneuptime package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.34
- Patched version(s): 10.0.34
References
Related Issues
- OneUptime has WhatsApp Resend Verification Authorization Bypass - CVE-2026-30959
- OpenLearnX: Critical Authentication Bypass via JWT Signature Verification Disabled Leading to Account Takeover - CVE-2026-44720
- dcap-qvl has Missing Verification for QE Identity - CVE-2026-22696
- jsrsasign: Negative Exponent Handling Leads to Signature Verification Bypass - CVE-2026-4602
You might also like:
- Tags:
- npm
- oneuptime
Anything's wrong? Let us know Last updated on March 20, 2026


