VYPR

Alloy

by Grafana

Source repositories

CVEs (2)

  • CVE-2026-75889HigAug 27, 2026
    risk 0.50cvss 7.7epss 0.00

    Grafana Alloy’s prometheus.operator.servicemonitors component allows a user who can create or modify ServiceMonitor resources in a watched namespace to specify an arbitrary local file through bearerTokenFile. Alloy reads the file and sends its contents as a bearer token to an…

  • CVE-2024-8975HigSep 25, 2024
    risk 0.40cvss 7.3epss 0.00

    Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.