Security Vulnerabilities in Bubble

Mar 5, 2026 - 7:29 AM

https://megagrass.com/community/question-and-answer/forums/4133/topics/3188696 COPY
  • As a part of selling our solution to enterprise customers we complete penetration testing regularly. The results from which identify which elements of the Bubble environment (outside the control of the application developer) that are out of compliance with current GDPR, PCI DSS and OWASP ASVS requirements.

    Where should these results be sent? Does anyone care, that a vulnerability in the Bubble environment immediately prevents 100% of its customers being able to claim GDPR compliance?

    Our last round of testing has identified two libraries preventing GDPR compliance being granted and raft of others that a low vulnerabilities. Where do we send this information?

    Or is the answer that such vulnerabilities should be hashed out here on the forum? Looking through the forum, the tendency is to try and shut these posts down as fast as possible rather than establish a proper communication flow. Thoughts?

    0
  • I’ve used an ip booter from DarkVR https://thedarkvr.su/ for checking how my own servers handle heavy traffic, and the setup was quick thanks to the crypto payments and fast activation. The log‑free approach helped me feel safer doing controlled tests, and the mix of Layer‑4 and Layer‑7 options made it easy to try different scenarios without overthinking the tech side.

    0