CVE-2026-21726
EUVD-2026-2310015.04.2026, 20:16
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}
Thanks to Prasanth Sundararajan for reporting this vulnerability.Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| grafana | loki | 𝑥 < 3.6.4 |
𝑥
= Vulnerable software versions