Impact
SigNoz versions 0.88.0 through 0.141.0 do not apply authorization wrappers to the trace‑funnel analytics endpoints in the HTTP handler. As a result, an unauthenticated attacker can submit arbitrary funnel definitions and receive detailed trace analytics that include identifiers, durations, span counts, service topology, and error activity without any credentials.
Affected Systems
All SigNoz deployments running any version from 0.88.0 up to and including 0.141.0 are affected. The vulnerable functionality resides in the HTTP trace‑funnel analytics endpoints exposed by the SigNoz query service.
Risk and Exploitability
The CV score of 8.8 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request to the trace‑funnel analytics endpoint, requiring no authentication. Successful exploitation grants access to detailed trace analytics data without credentials.
OpenCVE Enrichment