5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
2 packages
- loki-tool
- loki
Loki Path Traversal - CVE-2021-36156 Bypass
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace} Thanks to Prasanth Sundararajan for reporting this vulnerability.
References
-
https://grafana.com/security/security-advisories/cve-2026-21726 vendor-advisory
Affected products
- <3.5.9
Matching in nixpkgs
pkgs.grafana-loki
Like Prometheus, but for logs
pkgs.python312Packages.python-logging-loki
Python logging handler for Loki
pkgs.python313Packages.python-logging-loki
Python logging handler for Loki
pkgs.python314Packages.python-logging-loki
Python logging handler for Loki
pkgs.grafanaPlugins.grafana-lokiexplore-app
Browse Loki logs without the need for writing complex queries
pkgs.python312Packages.pysigma-backend-loki
Library to support the loki backend for pySigma
pkgs.python313Packages.pysigma-backend-loki
Library to support the loki backend for pySigma
pkgs.python314Packages.pysigma-backend-loki
Library to support the loki backend for pySigma
Ignored packages (2)
pkgs.loki
C++ library of designs, containing flexible implementations of common design patterns and idioms
pkgs.loki-tool
Tool for custom firmware on AT&T/Verizon Samsung and LG devices
-
nixos-unstable 0-unstable-2016-06-27
- nixpkgs-unstable 0-unstable-2016-06-27
- nixos-unstable-small 0-unstable-2016-06-27
Package maintainers
-
@mmahut Marek Mahut <marek.mahut@gmail.com>
-
@globin Robin Gloster <mail@glob.in>
-
@emilylange Emily Lange <nix@emilylange.de>
-
@ryan4yin Ryan Yin <xiaoyin_c@qq.com>
-
@loispostula Loïs Postula <lois@postu.la>
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>
-
@peterromfeldhk Peter Romfeld <peter.romfeld.hk@gmail.com>