CVE-2023-26141: Contribsys Sidekiq

Medium severity, CVSS 4.9. EPSS: 0.9% chance of exploitation in the next 30 days.

Versions of the package sidekiq before 7.1.3 are vulnerable to Denial of Service (DoS) due to insufficient checks in the dashboard-charts.js file. An attacker can exploit this vulnerability by manipulating the localStorage value which will cause excessive polling requests.

Affected products

  • Contribsys Sidekiq: before 6.5.10 (fixed in 6.5.10); from 7.0, before 7.1.3 (fixed in 7.1.3)

Published 2023-09-14. Last modified 2026-06-17.