Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

4Nk1T

#17133of 57,427
17.3Total CVSS
Vulnerabilities · 2
High
2
PT-2026-95006
8.5
2026-09-17
Signoz · Signoz · CVE-2026-93292
**Name of the Vulnerable Software and Affected Versions** SigNoz versions 0.88.0 through 0.142.0 **Description** Authenticated attackers can execute arbitrary SQL queries and retrieve results in HTTP responses. This occurs because the trace-funnel analytics endpoints interpolate the `service name` and `span name` fields into ClickHouse string literals without proper escaping. **Recommendations** Update SigNoz to version 0.142.1.
PT-2026-93909
8.8
2026-09-16
Signoz · Signoz · CVE-2026-92729
**Name of the Vulnerable Software and Affected Versions** SigNoz versions 0.88.0 through 0.141.0 **Description** The HTTP handler fails to apply authorization wrappers to trace-funnel analytics endpoints. This allows unauthenticated attackers to submit arbitrary funnel definitions to retrieve trace analytics, including identifiers, durations, span counts, service topology, and error activity, without providing credentials. **Recommendations** Update SigNoz to a version later than 0.141.0.