Showing 2 vulnerabilities on this page for Loki

Signals CISA KEV Ransomware Nuclei
Grafana vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Loki detected_fields query limits results in unbounded memory allocation

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

CWE-770Jul 16, 2026
CVSS7.5v3.1EPSS0.263%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Loki Path Traversal - CVE-2021-36156 Bypass

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.

CWE-22CWE-601Apr 15, 2026
CVSS5.3v3.1EPSS0.409%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX