All 4 CVE vulnerabilities found in signoz, with AI-generated Chinese analysis, references, and POCs.
Vendor: SigNoz
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-92729 | SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints CWE-306 | 8.2 | High | 2026-09-16 |
| CVE-2026-63094 | SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft CWE-601 | 8.1 | High | 2026-07-17 |
| CVE-2026-57956 | SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules CWE-639 | 6.4 | Medium | 2026-06-29 |
| CVE-2026-57955 | SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter CWE-89 | 8.5 | High | 2026-06-29 |
All 4 known CVE vulnerabilities affecting signoz with full Chinese analysis, references, and POCs where available.