CVE-2026-21726
ADVISORY - githubSummary
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}
Thanks to Prasanth Sundararajan for reporting this vulnerability.
Common Weakness Enumeration (CWE)
ADVISORY - nist
ADVISORY - github
URL Redirection to Untrusted Site ('Open Redirect')
NIST
CREATED
UPDATED
ADVISORY IDCVE-2026-21726
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)
CVSS SCORE
5.3mediumGitHub
CREATED
UPDATED
ADVISORY IDGHSA-497x-rrr9-68jp
EXPLOITABILITY SCORE
3.9
EXPLOITS FOUND
-
COMMON WEAKNESS ENUMERATION (CWE)