Outage in Bubble

Popups displaying crypto advertising

Resolved Major
October 30, 2024 - Started 7 months ago - Lasted about 3 hours
Official incident page

Need to monitor Bubble outages?
Stay on top of outages with IsDown. Monitor the official status pages of all your vendors, SaaS, and tools, including Bubble, and never miss an outage again.
Start Free Trial

Outage Details

A 3rd party library used by Bubble as well as by many Bubble-built apps has been hacked to display crypto advertising. Information about this incident can be found here: https://github.com/LottieFiles/lottie-player/issues/255 We are currently working on removing the compromised version of the dependency, as well as providing instructions to our users to fix this if it impacts their own apps
Latest Updates ( sorted recent to last )
RESOLVED 7 months ago - at 10/31/2024 12:17AM

The maintainers of Lottie announced that they've addressed the situation: https://github.com/LottieFiles/lottie-player/issues/254#issuecomment-2448685876

At this time, we believe the situation should be resolved for all apps

MONITORING 7 months ago - at 10/30/2024 10:20PM

We've made the below fix available to Dedicated boxes and apps on the Scheduled release tier. If you are on Dedicated, please use your Dedicated manager to update your cluster to the latest version to take advantage of the fix. Alternatively, you can uninstall plugins that depend on LottieFiles.

If you are plugin maintainer, please check if your plugin uses LottieFiles and if so, please update to a safe version (2.0.4). We are coordinating directly with a handful of our most-installed plugins. Canvas and LottieFiles plugins have been updated.

IDENTIFIED 7 months ago - at 10/30/2024 09:38PM

We just deployed a fix to automatically detect references to the compromised version (unpkg.com/@lottiefiles/lottie-player@latest) in Bubble-hosted html and replace it with a safe version (unpkg.com/@lottiefiles/lottie-player@2.0.4). We believe this will fix many/most 3rd party plugins that depend on Lottie Files, but we are continuing to investigate

IDENTIFIED 7 months ago - at 10/30/2024 09:16PM

A 3rd party library used by Bubble as well as by many Bubble-built apps has been hacked to display crypto advertising. Information about this incident can be found here: https://github.com/LottieFiles/lottie-player/issues/255

We are currently working on removing the compromised version of the dependency, as well as providing instructions to our users to fix this if it impacts their own apps

Latest Bubble outages

Brazil outage - 8 days ago

All Third-Party Status Pages in One Dashboard

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 4200 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook