PT-2026-3780 · Pyroscope · Pyroscope
CVE-2025-41118
·
Published
2026-01-02
·
Updated
2026-08-03
CVSS v3.1
9.4
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Pyroscope versions prior to 1.15.2
Pyroscope versions prior to 1.16.1
Description
When configured to use Tencent Cloud Object Storage (COS) as the storage backend, the Pyroscope API may expose the
secret key configuration value. An attacker with direct access to the API can extract this sensitive information.Recommendations
Update to version 1.15.2 or above.
Update to version 1.16.1 or above.
Limit public internet exposure of the database to ensure it is only accessible by trusted users or internal systems.
Exploit
Fix
Incorrect Permission
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pyroscope