VYPR
Vendor

SigNoz

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-93426HigSep 17, 2026
    risk 0.48cvss 8.5epss 0.00

    SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_range API, allowing authenticated users to inject SQL. Attackers with Viewer role or higher can embed backticks and quotes in field names to break out of identifiers and…

  • CVE-2026-93292HigSep 17, 2026
    risk 0.48cvss 8.5epss 0.00

    SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step…

  • CVE-2026-92729HigSep 16, 2026
    risk 0.46cvss 8.2epss 0.01

    SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts,…

  • CVE-2026-63094HigJul 17, 2026
    risk 0.00cvss 8.1epss 0.00

    SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions…

  • CVE-2026-57956MedJun 29, 2026
    risk 0.00cvss 6.4epss 0.00

    SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to filter by organization ID. Attackers can read, edit, and…

  • CVE-2026-57955HigJun 29, 2026
    risk 0.00cvss 8.5epss 0.00

    SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule…