<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:signoz:signoz:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3asignozsignoz/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 16 Sep 2026 19:52:24 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3asignozsignoz/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in SigNoz Trace-Funnel Analytics</title><link>https://feed.craftedsignal.io/briefs/2026-09-signoz-auth-bypass/</link><pubDate>Wed, 16 Sep 2026 19:52:24 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-signoz-auth-bypass/</guid><description>SigNoz versions 0.88.0 through 0.141.0 contain an authorization bypass vulnerability allowing unauthenticated remote attackers to query sensitive trace analytics via the trace-funnel endpoint.</description><content:encoded><![CDATA[<p>SigNoz versions 0.88.0 through 0.141.0 contain a critical authorization bypass vulnerability within the application's trace-funnel analytics endpoints. The vulnerability stems from a failure to implement necessary authorization wrappers on specific HTTP handlers responsible for processing trace-funnel requests. This oversight allows unauthenticated remote attackers to submit arbitrary funnel definitions to the API. By interacting with these unprotected endpoints, attackers can exfiltrate sensitive observability data, including trace identifiers, request durations, span counts, internal service topology, and error activity metrics. Because these endpoints do not validate user credentials, this vulnerability poses a significant risk for unauthorized information disclosure of internal system architecture and operational telemetry. Defending against this threat requires identifying and restricting access to the affected funnel analytics endpoints or upgrading to a patched version once available.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability results in unauthorized exposure of sensitive operational data. Successful exploitation allows an attacker to map service dependencies, identify high-frequency error patterns, and monitor traffic volumes, which can be used to inform further reconnaissance against the internal network. No specific victim counts are currently available, but any organization running versions 0.88.0 through 0.141.0 is at risk of remote telemetry exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Monitor webserver access logs for anomalous POST requests directed at trace-funnel analytic endpoints originating from unauthorized IP ranges.</li>
<li>Audit ingress traffic to identify unauthenticated requests to SigNoz API paths associated with trace analytics.</li>
<li>Implement strict network-level access control (e.g., WAF rules or VPN-only access) for the SigNoz API until an upgrade to a patched version is completed.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>authorization-bypass</category><category>api-security</category><category>observability</category><category>sql-injection</category><category>vulnerability</category><category>web-application</category><category>webserver</category><category>injection</category></item></channel></rss>