CVE Feed

    Dashboard / CVE / CVE-2026-57955

    CVE-2026-57955

    SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-history endpoints. Attackers can manipulate the unsanitized rule ID interpolated into ClickHouse queries to read all stored traces, logs, and metrics, or abuse the url() function to perform server-side request forgery.

    Published:Jun 29, 2026
    Last Modified:Jul 1, 2026
    EPS:Jun 29, 2026
    EPSS Score:0.00235
    CVSS Score:8.5

    Affected Products

    Vendor
    Signoz
    Product
    Signoz

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High