CVE-2026-93292

Source
https://cve.org/CVERecord?id=CVE-2026-93292
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93292.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93292
Aliases
  • GHSA-w5pf-xwjh-vr5v
Published
2026-09-17T16:26:42Z
Modified
2026-09-22T11:30:58Z
Severity
  • 8.4 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N CVSS Calculator
Summary
SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders
Details

SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-89"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93292.json"
}
References

Affected packages

Git / github.com/signoz/signoz

Affected ranges

Type
GIT
Repo
https://github.com/signoz/signoz
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0.88.0"
        },
        {
            "fixed":  "0.142.1"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.100.0
v0.100.1
v0.101.0
v0.101.0-rc.1
v0.102.0
v0.102.1
v0.103.0
v0.103.1
v0.104.0
v0.104.0-cloud.1
v0.105.0
v0.105.1
v0.106.0
v0.107.0
v0.108.0
v0.108.0-rc.1
v0.109.0
v0.109.1
v0.109.2
v0.109.3
v0.110.0
v0.110.1
v0.111.0
v0.112.0
v0.112.1
v0.113.0
v0.113.0-rc.1
v0.114.0
v0.114.1
v0.115.0
v0.116.0
v0.116.1
v0.117.0
v0.117.1
v0.118.0
v0.119.0
v0.120.0
v0.121.0
v0.121.1
v0.122.0
v0.123.0
v0.124.0
v0.125.0
v0.125.1
v0.126.0
v0.126.1
v0.126.3-rc.1
v0.127.0
v0.127.1
v0.128.0
v0.129.0
v0.130.0
v0.130.1
v0.131.0
v0.131.1
v0.132.0
v0.132.0-rc.1
v0.132.0-rc.2
v0.132.1
v0.132.2
v0.133.0
v0.134.0
v0.134.0-cloud.1
v0.134.0-cloud.2
v0.135.0
v0.135.0-cloud.1
v0.135.0-cloud.2
v0.135.0-cloud.3
v0.135.0-cloud.4
v0.135.0-cloud.5
v0.135.1
v0.136.0
v0.136.1
v0.137.0
v0.137.1
v0.138.0
v0.139.0
v0.140.0
v0.141.0
v0.141.1
v0.142.0
v0.88.0
v0.88.1
v0.89.0
v0.90.0
v0.90.1
v0.91.0
v0.91.1
v0.92.0
v0.92.0-cloud.1
v0.92.0-rc.1
v0.92.0-rc.5
v0.92.1
v0.92.2
v0.93.0
v0.93.0-cloud.1
v0.93.0-cloud.2
v0.93.0-cloud.3
v0.93.0-rc.1
v0.93.0-rc.2
v0.93.0-rc.3
v0.94.0
v0.94.1
v0.94.1-cloud.1
v0.95.0
v0.95.1
v0.95.1-cloud.1
v0.96.0
v0.96.1
v0.97.0
v0.97.0-rc.1
v0.97.0-rc.2
v0.97.0-rc.3
v0.97.1
v0.98.0
v0.98.0-rc.0
v0.98.0-rc.1
v0.99.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93292.json"