VYPR
High severity8.5NVD Advisory· Published Sep 17, 2026

CVE-2026-93292

CVE-2026-93292

Description

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • SigNoz/Signozreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 0.88.0 <= version < 0.142.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.