Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 19 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Signoz
Signoz signoz |
|
| Vendors & Products |
Signoz
Signoz signoz |
Thu, 17 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses. | |
| Title | SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-21T20:53:34.895Z
Reserved: 2026-09-17T16:17:11.416Z
Link: CVE-2026-93292
Updated: 2026-09-21T20:53:30.443Z
Status : Received
Published: 2026-09-17T17:18:16.903
Modified: 2026-09-21T21:17:17.560
Link: CVE-2026-93292
No data.
OpenCVE Enrichment
Updated: 2026-09-19T20:45:17Z