Known Vulnerabilities for Loki by Grafana
Listed below are 2 of the newest known vulnerabilities associated with "Loki" by "Grafana".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-42129 json | The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user ... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2026-21726 json | The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double en... | Not Provided | 2026-04-15 | 2026-04-20 |
| CVE-2026-10601 json | The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths wit... | Not Provided | 2026-06-22 | 2026-06-22 |
| CVE-2021-36156 json | An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rul... | 5.3 - MEDIUM | 2021-08-03 | 2021-09-14 |