Regular Expression Vulnerability in Checkmate by Bluewave Labs
CVE-2026-70656
4.9MEDIUM
What is CVE-2026-70656?
An authentication issue in Checkmate allows an admin or superadmin to insert a malicious regular expression in the expectedValue field for HTTP monitor matching. This vulnerability arises due to the synchronous evaluation of the regex against untrusted HTTP response bodies, leading to a potential Denial of Service (DoS) by freezing API endpoints and disrupting WebSocket connections. Users are strongly advised to upgrade to version 3.9.2, which resolves this critical issue.
Affected Version(s)
Checkmate >= 3.5.1, < 3.9.2
