Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-39087 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-04-23 |
| Vendor | Ntfy |
| Product | ntfy |
| CVSS Score | 9.8 (critical) |
| EPSS Score | 0.2% (percentile: 48%) |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function.
Required Actions
Upgrade Ntfy to version 2.21 or later immediately. Given the maximum impact of this vulnerability (unauthenticated remote code execution), the update should be prioritized — especially for instances exposed to the Internet.
Who Is Affected?
This vulnerability affects ntfy by Ntfy. All self-hosted ntfy.sh server installations running a version prior to 2.21 are affected. Verify the version deployed across your infrastructure.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
