Loki
This hub aggregates every CVE we track for Loki, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
0
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM2HIGH1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
0
0
1
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Loki.
- CVE-2026-21729Loki detected_fields query limits results in unbounded memory allocation7.5
- CVE-2026-21726Loki Path Traversal - CVE-2021-36156 Bypass5.3
- CVE-2021-36156An issue was discovered in Grafana Loki through 2.2.1. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../.....5.3
Product normalization is registry-driven with AI assist and human review. How it works