github.com
https://github.com/grafana/loki CVE-2026-21726
MEDIUM
Loki Path Traversal - CVE-2021-36156 Bypass
Record summary
CVE-2026-21726 has a selected CVSS score of 5.3 (medium).
Description
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 15, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unaffected | CVE List | 2.3.0 to < 3.5.9 | affected |
github.com/grafana/loki/v3Browse Go / github.com/grafana/loki/v3 | GitHub Advisory | Before 3.6.4 · Fixed in 3.6.4 | affected |
References
3grafana.comVendor advisory
https://grafana.com/security/security-advisories/cve-2026-21726 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-21726