{"id":"CVE-2026-93292","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-93292","summary":"SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse…","details":"SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.","published":"2026-09-17T17:18:16.903","modified":"2026-09-17T17:18:16.903","cvss":{"score":8.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25","label":"SigNoz/signoz@8286e78"},"references":[{"type":"WEB","url":"https://github.com/SigNoz/signoz"},{"type":"WEB","url":"https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/modules/tracefunnel/clickhouse_queries.go#L498-L499"},{"type":"WEB","url":"https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-service/app/http_handler.go#L4081-L4086"},{"type":"WEB","url":"https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25"},{"type":"WEB","url":"https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d"},{"type":"WEB","url":"https://github.com/SigNoz/signoz/releases/tag/v0.142.1"},{"type":"WEB","url":"https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/signoz-0.88.0-before-0.142.1-sql-injection-in-trace-funnel-analytics-query-builders"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T17:18:16.903"}}