CVE-2026-93292 | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
- 🔗 github.com/SigNoz/signoz/security/advisories/GHSA-w5…
- 🔗 github.com/SigNoz/signoz/commit/8e00c0405697659bd499…
- 🔗 github.com/SigNoz/signoz/commit/8286e787b296b291a26a…
- 🔗 github.com/SigNoz/signoz/releases/tag/v0.142.1
- 🔗 github.com/SigNoz/signoz/blob/v0.142.0/pkg/modules/t…
- 🔗 github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-ser…
- 🔗 github.com/SigNoz/signoz
- 🔗 www.vulncheck.com/advisories/signoz-0.88.0-before-0.142.1-s…
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-09-06 | 2026-09-23 |
|---|---|---|
| ≥90 % | 0 | 491 |
| ≥50 % | 0 | 1475 |
| ≥10 % | 0 | 0 |
| <10 % | 300 | 0 |
CVE-2026-93292 | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.
SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attacker
Noch keine Analyse zu CVE-2026-93292
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.