Search
Find a vulnerability
Search criteria
16 vulnerabilities by SigNoz
CVE-2026-97056 (GCVE-0-2026-97056)
Vulnerability from nvd – Published: 2026-09-24 01:53 – Updated: 2026-09-24 12:56
VLAI
EPSS
VEX
Title
SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass
Summary
SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer's DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account — for example from a stolen browser session or from a user being offboarded — retains the account's full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 12:55 UTC
CWE
- CWE-613 - Insufficient Session Expiration
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/faaed20dbd | patch |
| https://github.com/SigNoz/signoz/commit/e2e9173986 | patch |
| https://github.com/SigNoz/signoz/commit/b02aae2db3 | patch |
| https://github.com/SigNoz/signoz/commit/c122bc09b4 | patch |
| https://www.vulncheck.com/advisories/signoz-befor… | third-party-advisory |
Impacted products
Date Public
2026-09-23 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97056",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T12:55:59.241523Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T12:56:55.730Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.143.0",
"status": "affected",
"version": "0.98.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.143.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user\u0027s existing login sessions when the user\u0027s password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer\u0027s DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account \u2014 for example from a stolen browser session or from a user being offboarded \u2014 retains the account\u0027s full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-613",
"description": "Insufficient Session Expiration",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T01:53:04.486Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xrgp-3fq4-xg83)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/faaed20dbd"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/e2e9173986"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/b02aae2db3"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/c122bc09b4"
},
{
"name": "VulnCheck Advisory: SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-before-0.143.0-insufficient-session-expiration-authentication-bypass"
}
],
"title": "SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97056",
"datePublished": "2026-09-24T01:53:04.486Z",
"dateReserved": "2026-09-23T23:51:32.670Z",
"dateUpdated": "2026-09-24T12:56:55.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97055 (GCVE-0-2026-97055)
Vulnerability from nvd – Published: 2026-09-24 01:53 – Updated: 2026-09-24 12:58
VLAI
EPSS
VEX
Title
SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret
Summary
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenizer was the default provider, any such deployment is affected. An unauthenticated attacker who knows the ID of an existing user can forge a valid session token for that user — including an administrator — by signing the id, orgId and email claims with an empty key; the organization ID (and whether an email is registered) can be obtained without authentication from /api/v2/sessions/context. A forged refresh token can be exchanged at /api/v2/sessions/rotate for a new token pair and cannot be revoked, so it remains usable for its full lifetime (30 days by default). Fixed in v0.143.0, which requires a JWT secret when the jwt provider is selected and changes the default provider to opaque.
Severity
8.1 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 12:57 UTC
CWE
- CWE-1188 - Initialization of a Resource with an Insecure Default
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/67895d366d | patch |
| https://github.com/SigNoz/signoz/commit/b02aae2db3 | patch |
| https://www.vulncheck.com/advisories/signoz-befor… | third-party-advisory |
Impacted products
Date Public
2026-09-23 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97055",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T12:57:48.983290Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T12:58:15.178Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-c26w-g4j8-39m2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.143.0",
"status": "affected",
"version": "0.8.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.143.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "PLpaPLpa"
}
],
"datePublic": "2026-09-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenizer was the default provider, any such deployment is affected. An unauthenticated attacker who knows the ID of an existing user can forge a valid session token for that user \u2014 including an administrator \u2014 by signing the id, orgId and email claims with an empty key; the organization ID (and whether an email is registered) can be obtained without authentication from /api/v2/sessions/context. A forged refresh token can be exchanged at /api/v2/sessions/rotate for a new token pair and cannot be revoked, so it remains usable for its full lifetime (30 days by default). Fixed in v0.143.0, which requires a JWT secret when the jwt provider is selected and changes the default provider to opaque."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1188",
"description": "Initialization of a Resource with an Insecure Default",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T01:53:03.455Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-c26w-g4j8-39m2)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-c26w-g4j8-39m2"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/67895d366d"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/b02aae2db3"
},
{
"name": "VulnCheck Advisory: SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-before-0.143.0-authentication-bypass-via-empty-jwt-secret"
}
],
"title": "SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97055",
"datePublished": "2026-09-24T01:53:03.455Z",
"dateReserved": "2026-09-23T23:51:32.670Z",
"dateUpdated": "2026-09-24T12:58:15.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93426 (GCVE-0-2026-93426)
Vulnerability from nvd – Published: 2026-09-17 21:19 – Updated: 2026-09-18 20:05
VLAI
EPSS
VEX
Title
SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names
Summary
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 20:05 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
9 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/8e00c0405… | patch |
| https://github.com/SigNoz/signoz/commit/9c886be12… | patch |
| https://github.com/SigNoz/signoz/releases/tag/v0.142.0 | release-notes |
| https://github.com/SigNoz/signoz/blob/v0.141.1/pk… | technical-description |
| https://github.com/SigNoz/signoz/blob/v0.141.1/pk… | technical-description |
| https://github.com/SigNoz/signoz/blob/v0.141.1/pk… | technical-description |
| https://github.com/SigNoz/signoz | product |
| https://www.vulncheck.com/advisories/signoz-0.87.… | third-party-advisory |
Impacted products
Date Public
2026-09-17 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93426",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:05:17.818798Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T20:05:37.112Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.142.0",
"status": "affected",
"version": "0.87.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.142.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "alexwaira"
},
{
"lang": "en",
"type": "finder",
"value": "tonghuaroot"
},
{
"lang": "en",
"type": "finder",
"value": "dodge1218"
},
{
"lang": "en",
"type": "finder",
"value": "456789TZ"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T21:19:12.144Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-q3h7-gpc9-2rxc)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc"
},
{
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d"
},
{
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/9c886be12015c43a1465af3532b3c3afbec6bebc"
},
{
"name": "SigNoz v0.142.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.142.0"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/querybuilder/fallback_expr.go#L16-L22"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/telemetrymetadata/field_mapper.go#L79-L87"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/apiserver/signozapiserver/querier.go#L26"
},
{
"tags": [
"product"
],
"url": "https://github.com/SigNoz/signoz"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-0.87.0-before-0.142.0-sql-injection-in-v5-query-builder-field-key-names"
}
],
"title": "SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93426",
"datePublished": "2026-09-17T21:19:12.144Z",
"dateReserved": "2026-09-17T21:00:02.150Z",
"dateUpdated": "2026-09-18T20:05:37.112Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93292 (GCVE-0-2026-93292)
Vulnerability from nvd – Published: 2026-09-17 16:26 – Updated: 2026-09-21 20:53
VLAI
EPSS
VEX
Title
SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders
Summary
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 20:53 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/8e00c0405… | patch |
| https://github.com/SigNoz/signoz/commit/8286e787b… | patch |
| https://github.com/SigNoz/signoz/releases/tag/v0.142.1 | release-notes |
| https://github.com/SigNoz/signoz/blob/v0.142.0/pk… | technical-description |
| https://github.com/SigNoz/signoz/blob/v0.142.0/pk… | technical-description |
| https://github.com/SigNoz/signoz | product |
| https://www.vulncheck.com/advisories/signoz-0.88.… | third-party-advisory |
Impacted products
Date Public
2026-09-17 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93292",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T20:53:09.251070Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T20:53:34.895Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.142.1",
"status": "affected",
"version": "0.88.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.142.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "4NK1T"
},
{
"lang": "en",
"type": "finder",
"value": "axel-corsiez"
},
{
"lang": "en",
"type": "finder",
"value": "morimori-dev"
},
{
"lang": "en",
"type": "finder",
"value": "newugly"
},
{
"lang": "en",
"type": "finder",
"value": "thaidn (Calif.io, in collaboration with Anthropic)"
},
{
"lang": "en",
"type": "finder",
"value": "hackchang"
},
{
"lang": "en",
"type": "finder",
"value": "Scott Moore - VulnCheck"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:26:42.867Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-w5pf-xwjh-vr5v)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v"
},
{
"name": "Partial fix, released 0.142.0",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d"
},
{
"name": "Residual two-step fix, released 0.142.1",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25"
},
{
"name": "SigNoz v0.142.1 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.142.1"
},
{
"name": "Residual unescaped interpolation at the last affected release",
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/modules/tracefunnel/clickhouse_queries.go#L498-L499"
},
{
"name": "The six affected analytics routes and their view-access wrapper",
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-service/app/http_handler.go#L4081-L4086"
},
{
"tags": [
"product"
],
"url": "https://github.com/SigNoz/signoz"
},
{
"name": "VulnCheck Advisory: SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-0.88.0-before-0.142.1-sql-injection-in-trace-funnel-analytics-query-builders"
}
],
"title": "SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93292",
"datePublished": "2026-09-17T16:26:42.867Z",
"dateReserved": "2026-09-17T16:17:11.416Z",
"dateUpdated": "2026-09-21T20:53:34.895Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92729 (GCVE-0-2026-92729)
Vulnerability from nvd – Published: 2026-09-16 18:31 – Updated: 2026-09-21 18:18
VLAI
EPSS
VEX
Title
SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
Summary
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 18:16 UTC
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/pull/12817 | patchissue-tracking |
| https://github.com/SigNoz/signoz/commit/f78bd492d… | patch |
| https://github.com/SigNoz/signoz/releases/tag/v0.141.1 | release-notes |
| https://github.com/SigNoz/signoz/blob/v0.141.0/pk… | technical-description |
| https://github.com/SigNoz/signoz | product |
| https://www.vulncheck.com/advisories/signoz-0.88.… | third-party-advisory |
Impacted products
Date Public
2026-09-14 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92729",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T18:16:46.906855Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T18:18:36.036Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.141.1",
"status": "affected",
"version": "0.88.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "4NK1T"
},
{
"lang": "en",
"type": "finder",
"value": "lighthousekeeper1212"
},
{
"lang": "en",
"type": "finder",
"value": "0xVijay"
},
{
"lang": "en",
"type": "finder",
"value": "axel-corsiez"
},
{
"lang": "en",
"type": "finder",
"value": "morimori-dev"
},
{
"lang": "en",
"type": "finder",
"value": "PLpaPLpa"
},
{
"lang": "en",
"type": "finder",
"value": "newugly"
},
{
"lang": "en",
"type": "finder",
"value": "thaidn (Calif.io, in collaboration with Anthropic)"
},
{
"lang": "en",
"type": "finder",
"value": "hackchang"
},
{
"lang": "en",
"type": "finder",
"value": "Wenhao Wu (d3do-23), Southeast University"
}
],
"datePublic": "2026-09-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:31:19.245Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-v549-7j2x-qjm5)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5"
},
{
"name": "Pull Request #12817",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/pull/12817"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/f78bd492d8732f011bc96837cf9862db2df0783d"
},
{
"name": "SigNoz v0.141.1 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.141.1"
},
{
"name": "RegisterTraceFunnelsRoutes analytics routes registered without an authorization wrapper",
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.0/pkg/query-service/app/http_handler.go#L4073-L4086"
},
{
"tags": [
"product"
],
"url": "https://github.com/SigNoz/signoz"
},
{
"name": "VulnCheck Advisory: SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-0.88.0-through-0.141.0-missing-authentication-on-trace-funnel-analytics-endpoints"
}
],
"title": "SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92729",
"datePublished": "2026-09-16T18:31:19.245Z",
"dateReserved": "2026-09-16T17:40:23.128Z",
"dateUpdated": "2026-09-21T18:18:36.036Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63094 (GCVE-0-2026-63094)
Vulnerability from nvd – Published: 2026-07-17 14:22 – Updated: 2026-07-27 17:17 X_Open Source
VLAI
EPSS
VEX
Title
SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
Summary
SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-21 01:38 UTC
CWE
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/issues/11746 | technical-descriptionexploit |
| https://github.com/SigNoz/signoz/releases/tag/v0.134.0 | release-notes |
| https://github.com/SigNoz/signoz/pull/12172 | issue-tracking |
| https://github.com/SigNoz/signoz/commit/253ca7dd7… | patch |
| https://www.vulncheck.com/advisories/signoz-sso-o… | third-party-advisory |
Date Public
2026-06-16 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63094",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-21T01:38:52.091051Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-21T01:39:05.048Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "signoz",
"repo": "https://github.com/SigNoz/signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.134.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-06-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim\u0027s access and refresh tokens when they complete SSO authentication."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-345",
"description": "Insufficient Verification of Data Authenticity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-27T17:17:11.454Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"technical-description",
"exploit"
],
"url": "https://github.com/SigNoz/signoz/issues/11746"
},
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.134.0"
},
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/pull/12172"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/253ca7dd7eb4f7a32a694c249eb0d5d0804d5619"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-sso-oauth-state-manipulation-session-token-theft"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "SigNoz \u003c 0.134.0 SSO OAuth State Manipulation Session Token Theft",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-63094",
"datePublished": "2026-07-17T14:22:22.677Z",
"dateReserved": "2026-07-15T15:45:44.601Z",
"dateUpdated": "2026-07-27T17:17:11.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-57956 (GCVE-0-2026-57956)
Vulnerability from nvd – Published: 2026-06-29 17:22 – Updated: 2026-07-20 15:44 X_Open Source
VLAI
EPSS
VEX
Title
SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules
Summary
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
Severity
6.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-29 19:22 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/issues/11830 | issue-tracking |
| https://github.com/SigNoz/signoz/releases/tag/v0.133.0 | release-notes |
| https://github.com/SigNoz/signoz/pull/12117 | issue-tracking |
| https://www.vulncheck.com/advisories/signoz-cross… | third-party-advisory |
Date Public
2026-06-23 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-57956",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-29T19:22:20.395999Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-29T19:22:46.011Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/issues/11830"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/SigNoz/signoz",
"product": "signoz",
"repo": "https://github.com/SigNoz/signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.133.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-06-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations\u0027 alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-20T15:44:46.563Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/issues/11830"
},
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.133.0"
},
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/pull/12117"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-cross-organization-insecure-direct-object-reference-in-alert-rules"
}
],
"tags": [
"x_open-source"
],
"title": "SigNoz \u003c 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-57956",
"datePublished": "2026-06-29T17:22:45.706Z",
"dateReserved": "2026-06-26T13:59:33.048Z",
"dateUpdated": "2026-07-20T15:44:46.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-57955 (GCVE-0-2026-57955)
Vulnerability from nvd – Published: 2026-06-29 17:22 – Updated: 2026-07-14 21:34 X_Open Source
VLAI
EPSS
VEX
Title
SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter
Summary
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-29 18:38 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/issues/11747 | issue-tracking |
| https://www.vulncheck.com/advisories/signoz-sql-i… | third-party-advisory |
Date Public
2026-06-17 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-57955",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-29T18:38:51.565390Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-29T18:38:57.550Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/SigNoz/signoz",
"product": "signoz",
"repo": "https://github.com/SigNoz/signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThanOrEqual": "0.130.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-06-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-14T21:34:43.759Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/issues/11747"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-sql-injection-in-alert-history-endpoints-via-rule-id-parameter"
}
],
"tags": [
"x_open-source"
],
"title": "SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-57955",
"datePublished": "2026-06-29T17:22:22.444Z",
"dateReserved": "2026-06-26T13:59:33.048Z",
"dateUpdated": "2026-07-14T21:34:43.759Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97056 (GCVE-0-2026-97056)
Vulnerability from cvelistv5 – Published: 2026-09-24 01:53 – Updated: 2026-09-24 12:56
VLAI
EPSS
VEX
Title
SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass
Summary
SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user's existing login sessions when the user's password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer's DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account — for example from a stolen browser session or from a user being offboarded — retains the account's full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 12:55 UTC
CWE
- CWE-613 - Insufficient Session Expiration
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/faaed20dbd | patch |
| https://github.com/SigNoz/signoz/commit/e2e9173986 | patch |
| https://github.com/SigNoz/signoz/commit/b02aae2db3 | patch |
| https://github.com/SigNoz/signoz/commit/c122bc09b4 | patch |
| https://www.vulncheck.com/advisories/signoz-befor… | third-party-advisory |
Impacted products
Date Public
2026-09-23 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97056",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T12:55:59.241523Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T12:56:55.730Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.143.0",
"status": "affected",
"version": "0.98.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.143.0",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-09-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tokenizer (which was not the default before v0.143.0), do not revoke a user\u0027s existing login sessions when the user\u0027s password is reset with a reset token (UpdatePasswordByResetPasswordToken, reachable via POST /api/v2/factor_password/reset) or when the user is deleted (DeleteUser, reachable via DELETE /api/v2/users/{id}). Neither code path calls the tokenizer\u0027s DeleteTokensByUserID, so cached tokens and identities are left in place. An attacker who already holds a session token for the account \u2014 for example from a stolen browser session or from a user being offboarded \u2014 retains the account\u0027s full access, up to administrator, after a password reset until the token reaches its configured maximum lifetime (30 days by default), and after user deletion until the token next rotates (30 minutes by default). This defeats password reset and user deletion as a means of terminating access. The issue is fixed in v0.143.0."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.8,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-613",
"description": "Insufficient Session Expiration",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T01:53:04.486Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-xrgp-3fq4-xg83)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-xrgp-3fq4-xg83"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/faaed20dbd"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/e2e9173986"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/b02aae2db3"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/c122bc09b4"
},
{
"name": "VulnCheck Advisory: SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-before-0.143.0-insufficient-session-expiration-authentication-bypass"
}
],
"title": "SigNoz before 0.143.0 Insufficient Session Expiration Authentication Bypass",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97056",
"datePublished": "2026-09-24T01:53:04.486Z",
"dateReserved": "2026-09-23T23:51:32.670Z",
"dateUpdated": "2026-09-24T12:56:55.730Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97055 (GCVE-0-2026-97055)
Vulnerability from cvelistv5 – Published: 2026-09-24 01:53 – Updated: 2026-09-24 12:58
VLAI
EPSS
VEX
Title
SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret
Summary
SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenizer was the default provider, any such deployment is affected. An unauthenticated attacker who knows the ID of an existing user can forge a valid session token for that user — including an administrator — by signing the id, orgId and email claims with an empty key; the organization ID (and whether an email is registered) can be obtained without authentication from /api/v2/sessions/context. A forged refresh token can be exchanged at /api/v2/sessions/rotate for a new token pair and cannot be revoked, so it remains usable for its full lifetime (30 days by default). Fixed in v0.143.0, which requires a JWT secret when the jwt provider is selected and changes the default provider to opaque.
Severity
8.1 (High)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 12:57 UTC
CWE
- CWE-1188 - Initialization of a Resource with an Insecure Default
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/67895d366d | patch |
| https://github.com/SigNoz/signoz/commit/b02aae2db3 | patch |
| https://www.vulncheck.com/advisories/signoz-befor… | third-party-advisory |
Impacted products
Date Public
2026-09-23 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97055",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T12:57:48.983290Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T12:58:15.178Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-c26w-g4j8-39m2"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.143.0",
"status": "affected",
"version": "0.8.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.143.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "PLpaPLpa"
}
],
"datePublic": "2026-09-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOKENIZER_JWT_SECRET or the deprecated SIGNOZ_JWT_SECRET) to an empty string, and Config.Validate() does not reject the empty value, so a deployment that does not configure a secret starts up and both signs and verifies session tokens with an empty HMAC key. Because the JWT tokenizer was the default provider, any such deployment is affected. An unauthenticated attacker who knows the ID of an existing user can forge a valid session token for that user \u2014 including an administrator \u2014 by signing the id, orgId and email claims with an empty key; the organization ID (and whether an email is registered) can be obtained without authentication from /api/v2/sessions/context. A forged refresh token can be exchanged at /api/v2/sessions/rotate for a new token pair and cannot be revoked, so it remains usable for its full lifetime (30 days by default). Fixed in v0.143.0, which requires a JWT secret when the jwt provider is selected and changes the default provider to opaque."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-1188",
"description": "Initialization of a Resource with an Insecure Default",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T01:53:03.455Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-c26w-g4j8-39m2)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-c26w-g4j8-39m2"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/67895d366d"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/b02aae2db3"
},
{
"name": "VulnCheck Advisory: SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-before-0.143.0-authentication-bypass-via-empty-jwt-secret"
}
],
"title": "SigNoz before 0.143.0 Authentication Bypass via Empty JWT Secret",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97055",
"datePublished": "2026-09-24T01:53:03.455Z",
"dateReserved": "2026-09-23T23:51:32.670Z",
"dateUpdated": "2026-09-24T12:58:15.178Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93426 (GCVE-0-2026-93426)
Vulnerability from cvelistv5 – Published: 2026-09-17 21:19 – Updated: 2026-09-18 20:05
VLAI
EPSS
VEX
Title
SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names
Summary
SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-18 20:05 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
9 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/8e00c0405… | patch |
| https://github.com/SigNoz/signoz/commit/9c886be12… | patch |
| https://github.com/SigNoz/signoz/releases/tag/v0.142.0 | release-notes |
| https://github.com/SigNoz/signoz/blob/v0.141.1/pk… | technical-description |
| https://github.com/SigNoz/signoz/blob/v0.141.1/pk… | technical-description |
| https://github.com/SigNoz/signoz/blob/v0.141.1/pk… | technical-description |
| https://github.com/SigNoz/signoz | product |
| https://www.vulncheck.com/advisories/signoz-0.87.… | third-party-advisory |
Impacted products
Date Public
2026-09-17 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93426",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-18T20:05:17.818798Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-18T20:05:37.112Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.142.0",
"status": "affected",
"version": "0.87.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.142.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "alexwaira"
},
{
"lang": "en",
"type": "finder",
"value": "tonghuaroot"
},
{
"lang": "en",
"type": "finder",
"value": "dodge1218"
},
{
"lang": "en",
"type": "finder",
"value": "456789TZ"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and string literals, executing arbitrary ClickHouse SQL to read system tables and exfiltrate data."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T21:19:12.144Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-q3h7-gpc9-2rxc)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-q3h7-gpc9-2rxc"
},
{
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d"
},
{
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/9c886be12015c43a1465af3532b3c3afbec6bebc"
},
{
"name": "SigNoz v0.142.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.142.0"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/querybuilder/fallback_expr.go#L16-L22"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/telemetrymetadata/field_mapper.go#L79-L87"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.1/pkg/apiserver/signozapiserver/querier.go#L26"
},
{
"tags": [
"product"
],
"url": "https://github.com/SigNoz/signoz"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-0.87.0-before-0.142.0-sql-injection-in-v5-query-builder-field-key-names"
}
],
"title": "SigNoz 0.87.0 before 0.142.0 - SQL Injection in v5 Query Builder Field Key Names",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93426",
"datePublished": "2026-09-17T21:19:12.144Z",
"dateReserved": "2026-09-17T21:00:02.150Z",
"dateUpdated": "2026-09-18T20:05:37.112Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93292 (GCVE-0-2026-93292)
Vulnerability from cvelistv5 – Published: 2026-09-17 16:26 – Updated: 2026-09-21 20:53
VLAI
EPSS
VEX
Title
SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders
Summary
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 20:53 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/commit/8e00c0405… | patch |
| https://github.com/SigNoz/signoz/commit/8286e787b… | patch |
| https://github.com/SigNoz/signoz/releases/tag/v0.142.1 | release-notes |
| https://github.com/SigNoz/signoz/blob/v0.142.0/pk… | technical-description |
| https://github.com/SigNoz/signoz/blob/v0.142.0/pk… | technical-description |
| https://github.com/SigNoz/signoz | product |
| https://www.vulncheck.com/advisories/signoz-0.88.… | third-party-advisory |
Impacted products
Date Public
2026-09-17 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93292",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T20:53:09.251070Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T20:53:34.895Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.142.1",
"status": "affected",
"version": "0.88.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "0.142.1",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "4NK1T"
},
{
"lang": "en",
"type": "finder",
"value": "axel-corsiez"
},
{
"lang": "en",
"type": "finder",
"value": "morimori-dev"
},
{
"lang": "en",
"type": "finder",
"value": "newugly"
},
{
"lang": "en",
"type": "finder",
"value": "thaidn (Calif.io, in collaboration with Anthropic)"
},
{
"lang": "en",
"type": "finder",
"value": "hackchang"
},
{
"lang": "en",
"type": "finder",
"value": "Scott Moore - VulnCheck"
}
],
"datePublic": "2026-09-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.4,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "LOW",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T16:26:42.867Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-w5pf-xwjh-vr5v)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v"
},
{
"name": "Partial fix, released 0.142.0",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d"
},
{
"name": "Residual two-step fix, released 0.142.1",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25"
},
{
"name": "SigNoz v0.142.1 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.142.1"
},
{
"name": "Residual unescaped interpolation at the last affected release",
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/modules/tracefunnel/clickhouse_queries.go#L498-L499"
},
{
"name": "The six affected analytics routes and their view-access wrapper",
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-service/app/http_handler.go#L4081-L4086"
},
{
"tags": [
"product"
],
"url": "https://github.com/SigNoz/signoz"
},
{
"name": "VulnCheck Advisory: SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-0.88.0-before-0.142.1-sql-injection-in-trace-funnel-analytics-query-builders"
}
],
"title": "SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93292",
"datePublished": "2026-09-17T16:26:42.867Z",
"dateReserved": "2026-09-17T16:17:11.416Z",
"dateUpdated": "2026-09-21T20:53:34.895Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92729 (GCVE-0-2026-92729)
Vulnerability from cvelistv5 – Published: 2026-09-16 18:31 – Updated: 2026-09-21 18:18
VLAI
EPSS
VEX
Title
SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
Summary
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
Severity
SSVC
Exploitation: poc
Automatable: yes
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 18:16 UTC
Assigner
References
7 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/security/advisor… | vendor-advisory |
| https://github.com/SigNoz/signoz/pull/12817 | patchissue-tracking |
| https://github.com/SigNoz/signoz/commit/f78bd492d… | patch |
| https://github.com/SigNoz/signoz/releases/tag/v0.141.1 | release-notes |
| https://github.com/SigNoz/signoz/blob/v0.141.0/pk… | technical-description |
| https://github.com/SigNoz/signoz | product |
| https://www.vulncheck.com/advisories/signoz-0.88.… | third-party-advisory |
Impacted products
Date Public
2026-09-14 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92729",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T18:16:46.906855Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T18:18:36.036Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:golang/github.com/SigNoz/signoz",
"product": "signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.141.1",
"status": "affected",
"version": "0.88.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "4NK1T"
},
{
"lang": "en",
"type": "finder",
"value": "lighthousekeeper1212"
},
{
"lang": "en",
"type": "finder",
"value": "0xVijay"
},
{
"lang": "en",
"type": "finder",
"value": "axel-corsiez"
},
{
"lang": "en",
"type": "finder",
"value": "morimori-dev"
},
{
"lang": "en",
"type": "finder",
"value": "PLpaPLpa"
},
{
"lang": "en",
"type": "finder",
"value": "newugly"
},
{
"lang": "en",
"type": "finder",
"value": "thaidn (Calif.io, in collaboration with Anthropic)"
},
{
"lang": "en",
"type": "finder",
"value": "hackchang"
},
{
"lang": "en",
"type": "finder",
"value": "Wenhao Wu (d3do-23), Southeast University"
}
],
"datePublic": "2026-09-14T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.8,
"baseSeverity": "HIGH",
"privilegesRequired": "NONE",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 8.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-306",
"description": "Missing Authentication for Critical Function",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:31:19.245Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub Security Advisory (GHSA-v549-7j2x-qjm5)",
"tags": [
"vendor-advisory"
],
"url": "https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5"
},
{
"name": "Pull Request #12817",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/pull/12817"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/f78bd492d8732f011bc96837cf9862db2df0783d"
},
{
"name": "SigNoz v0.141.1 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.141.1"
},
{
"name": "RegisterTraceFunnelsRoutes analytics routes registered without an authorization wrapper",
"tags": [
"technical-description"
],
"url": "https://github.com/SigNoz/signoz/blob/v0.141.0/pkg/query-service/app/http_handler.go#L4073-L4086"
},
{
"tags": [
"product"
],
"url": "https://github.com/SigNoz/signoz"
},
{
"name": "VulnCheck Advisory: SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-0.88.0-through-0.141.0-missing-authentication-on-trace-funnel-analytics-endpoints"
}
],
"title": "SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92729",
"datePublished": "2026-09-16T18:31:19.245Z",
"dateReserved": "2026-09-16T17:40:23.128Z",
"dateUpdated": "2026-09-21T18:18:36.036Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-63094 (GCVE-0-2026-63094)
Vulnerability from cvelistv5 – Published: 2026-07-17 14:22 – Updated: 2026-07-27 17:17 X_Open Source
VLAI
EPSS
VEX
Title
SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
Summary
SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-21 01:38 UTC
CWE
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/issues/11746 | technical-descriptionexploit |
| https://github.com/SigNoz/signoz/releases/tag/v0.134.0 | release-notes |
| https://github.com/SigNoz/signoz/pull/12172 | issue-tracking |
| https://github.com/SigNoz/signoz/commit/253ca7dd7… | patch |
| https://www.vulncheck.com/advisories/signoz-sso-o… | third-party-advisory |
Date Public
2026-06-16 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-63094",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-21T01:38:52.091051Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-21T01:39:05.048Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "signoz",
"repo": "https://github.com/SigNoz/signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.134.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-06-16T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim\u0027s access and refresh tokens when they complete SSO authentication."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 7.6,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "PASSIVE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-601",
"description": "URL Redirection to Untrusted Site (\u0027Open Redirect\u0027)",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-345",
"description": "Insufficient Verification of Data Authenticity",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-27T17:17:11.454Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"technical-description",
"exploit"
],
"url": "https://github.com/SigNoz/signoz/issues/11746"
},
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.134.0"
},
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/pull/12172"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/SigNoz/signoz/commit/253ca7dd7eb4f7a32a694c249eb0d5d0804d5619"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-sso-oauth-state-manipulation-session-token-theft"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source"
],
"title": "SigNoz \u003c 0.134.0 SSO OAuth State Manipulation Session Token Theft",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-63094",
"datePublished": "2026-07-17T14:22:22.677Z",
"dateReserved": "2026-07-15T15:45:44.601Z",
"dateUpdated": "2026-07-27T17:17:11.454Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-57956 (GCVE-0-2026-57956)
Vulnerability from cvelistv5 – Published: 2026-06-29 17:22 – Updated: 2026-07-20 15:44 X_Open Source
VLAI
EPSS
VEX
Title
SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules
Summary
SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls.
Severity
6.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-29 19:22 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
4 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/issues/11830 | issue-tracking |
| https://github.com/SigNoz/signoz/releases/tag/v0.133.0 | release-notes |
| https://github.com/SigNoz/signoz/pull/12117 | issue-tracking |
| https://www.vulncheck.com/advisories/signoz-cross… | third-party-advisory |
Date Public
2026-06-23 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-57956",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-29T19:22:20.395999Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-29T19:22:46.011Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://github.com/SigNoz/signoz/issues/11830"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/SigNoz/signoz",
"product": "signoz",
"repo": "https://github.com/SigNoz/signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThan": "0.133.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-06-23T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations\u0027 alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and delete alert rules belonging to other organizations by exploiting the missing tenant isolation check, bypassing multi-tenant access controls."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "HIGH",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 6.1,
"baseSeverity": "MEDIUM",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "LOW",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "LOW",
"baseScore": 6.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:L",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-20T15:44:46.563Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/issues/11830"
},
{
"name": "Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/SigNoz/signoz/releases/tag/v0.133.0"
},
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/pull/12117"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-cross-organization-insecure-direct-object-reference-in-alert-rules"
}
],
"tags": [
"x_open-source"
],
"title": "SigNoz \u003c 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-57956",
"datePublished": "2026-06-29T17:22:45.706Z",
"dateReserved": "2026-06-26T13:59:33.048Z",
"dateUpdated": "2026-07-20T15:44:46.563Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-57955 (GCVE-0-2026-57955)
Vulnerability from cvelistv5 – Published: 2026-06-29 17:22 – Updated: 2026-07-14 21:34 X_Open Source
VLAI
EPSS
VEX
Title
SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter
Summary
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-06-29 18:38 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Assigner
References
2 references
| URL | Tags |
|---|---|
| https://github.com/SigNoz/signoz/issues/11747 | issue-tracking |
| https://www.vulncheck.com/advisories/signoz-sql-i… | third-party-advisory |
Date Public
2026-06-17 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-57955",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-06-29T18:38:51.565390Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-06-29T18:38:57.550Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/SigNoz/signoz",
"product": "signoz",
"repo": "https://github.com/SigNoz/signoz",
"vendor": "SigNoz",
"versions": [
{
"lessThanOrEqual": "0.130.1",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "George Chen"
}
],
"datePublic": "2026-06-17T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.3,
"baseSeverity": "HIGH",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "LOW",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "HIGH",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "LOW",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-07-14T21:34:43.759Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Researcher Disclosure",
"tags": [
"issue-tracking"
],
"url": "https://github.com/SigNoz/signoz/issues/11747"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/signoz-sql-injection-in-alert-history-endpoints-via-rule-id-parameter"
}
],
"tags": [
"x_open-source"
],
"title": "SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-57955",
"datePublished": "2026-06-29T17:22:22.444Z",
"dateReserved": "2026-06-26T13:59:33.048Z",
"dateUpdated": "2026-07-14T21:34:43.759Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}