VDB
Sign up
—

GO-2026-5551

ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function in heckel.io/ntfy

Quick fix

GO-2026-5551 — heckel.io/ntfy/v2: upgrade to the fixed version with the command below.

go get heckel.io/ntfy/v2@v2.22.0

Details

ntfy.sh allows a remote attacker to execute arbitrary code via the parseActions function in heckel.io/ntfy

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/heckel.io/ntfy
Introduced in: 0

No fixed version published yet for heckel.io/ntfy (go modules). Pin to a known-safe version or switch to an alternative.

Go/heckel.io/ntfy/v2
Introduced in: 0Fixed in: 2.22.0
Fixgo get heckel.io/ntfy/v2@v2.22.0

References