Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses. | |
| Title | SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-17T16:26:42.867Z
Reserved: 2026-09-17T16:17:11.416Z
Link: CVE-2026-93292
No data.
Status : Received
Published: 2026-09-17T17:18:16.903
Modified: 2026-09-17T17:18:16.903
Link: CVE-2026-93292
No data.
OpenCVE Enrichment
No data.