Vulnerabilities
Vulnerable Software
Grafana:  >> Loki  >> 2.4.2  Security Vulnerabilities
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-04-15


Contact Us

Shodan ® - All rights reserved