CVE-2026-21726
ADVISORY - githubSummary
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can read files at the Ruler API endpoint /loki/api/v1/rules/{namespace}
Thanks to Prasanth Sundararajan for reporting this vulnerability.
Common Weakness Enumeration (CWE)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
NIST
3.9
CVSS SCORE
5.3mediumGitHub
CVSS SCORE
5.3mediumAlpine
-
Chainguard
CGA-w6q8-cj25-57rp
-
minimos
MINI-2hgx-gh8q-r66m
-
minimos
MINI-3376-m49q-82jj
-
minimos
MINI-3wgj-6m78-mpf8
-
minimos
MINI-43q4-qxwp-6qpj
-
minimos
MINI-5hwp-xm7h-33rf
-
minimos
MINI-5p5x-gmq6-49x6
-
minimos
MINI-9cjh-8h5h-6r8p
-
minimos
MINI-9v53-pwqr-pj2w
-
minimos
MINI-9xj5-w7rv-r3qg
-
minimos
MINI-cc95-64vw-32m8
-
minimos
MINI-cqcr-qgp9-5wpc
-
minimos
MINI-ff7w-qg8c-jc9x
-
minimos
MINI-g29c-7xwp-5hhw
-
minimos
MINI-gxrj-9mrw-r8cm
-
minimos
MINI-h8xp-3pvj-q6mf
-
minimos
MINI-m2cj-h79x-rhgc
-
minimos
MINI-qffh-4xvv-h66q
-
minimos
MINI-qfm4-fp5v-2m77
-
minimos
MINI-qpcp-5x47-qh4g
-
minimos
MINI-v89m-7wq7-f559
-
minimos
MINI-vf2w-f8gp-2xw9
-
minimos
MINI-w66g-855v-4f99
-
minimos
MINI-wfgh-wchv-f2fg
-
minimos
MINI-x268-59h8-8693
-
minimos
MINI-x63h-rc69-r3hq
-