{"id":"CVE-2026-93292","summary":"SigNoz 0.88.0 before 0.142.1 - SQL Injection in Trace Funnel Analytics Query Builders","details":"SigNoz versions from 0.88.0 before 0.142.1 contain a SQL injection vulnerability in trace-funnel analytics endpoints that interpolate service_name and span_name fields into ClickHouse string literals without escaping. Authenticated attackers can inject SQL through funnel step definitions to execute arbitrary queries and read results in HTTP responses.","aliases":["GHSA-w5pf-xwjh-vr5v"],"modified":"2026-09-23T03:30:19.567151405Z","published":"2026-09-17T16:26:42.867Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93292.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93292.json"},{"type":"ADVISORY","url":"https://github.com/SigNoz/signoz/releases/tag/v0.142.1"},{"type":"ADVISORY","url":"https://github.com/SigNoz/signoz/security/advisories/GHSA-w5pf-xwjh-vr5v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93292"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/signoz-0.88.0-before-0.142.1-sql-injection-in-trace-funnel-analytics-query-builders"},{"type":"FIX","url":"https://github.com/SigNoz/signoz/commit/8286e787b296b291a26a14d20407a335fcfbac25"},{"type":"FIX","url":"https://github.com/SigNoz/signoz/commit/8e00c0405697659bd4994a5de446cf3028c0f76d"},{"type":"PACKAGE","url":"https://github.com/SigNoz/signoz"},{"type":"ARTICLE","url":"https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/modules/tracefunnel/clickhouse_queries.go#L498-L499"},{"type":"ARTICLE","url":"https://github.com/SigNoz/signoz/blob/v0.142.0/pkg/query-service/app/http_handler.go#L4081-L4086"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/signoz/signoz","events":[{"introduced":"9a3a8c8305b8ca9e493e0b12bc19db47775bc809"},{"fixed":"d1a382945ce2aa544059f24b95c47ddf5fef7434"},{"fixed":"8286e787b296b291a26a14d20407a335fcfbac25"},{"fixed":"8e00c0405697659bd4994a5de446cf3028c0f76d"}],"database_specific":{"extracted_events":[{"introduced":"0.88.0"},{"fixed":"0.142.1"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v0.142.0","v0.141.1","v0.141.0","v0.140.0","v0.139.0","v0.138.0","v0.137.1","v0.137.0","v0.136.1","v0.135.1","v0.136.0","v0.135.0-cloud.5","v0.135.0","v0.135.0-cloud.4","v0.135.0-cloud.3","v0.135.0-cloud.2","v0.135.0-cloud.1","v0.134.0","v0.134.0-cloud.2","v0.134.0-cloud.1","v0.133.0","v0.132.2","v0.132.1","v0.132.0","v0.131.1","v0.132.0-rc.2","v0.132.0-rc.1","v0.131.0","v0.130.1","v0.130.0","v0.129.0","v0.128.0","v0.127.1","v0.127.0","v0.126.3-rc.1","v0.126.1","v0.126.0","v0.125.1","v0.125.0","v0.124.0","v0.123.0","v0.122.0","v0.121.1","v0.121.0","v0.120.0","v0.119.0","v0.118.0","v0.117.1","v0.117.0","v0.116.0","v0.116.1","v0.115.0","v0.114.1","v0.114.0","v0.113.0","v0.113.0-rc.1","v0.112.1","v0.112.0","v0.111.0","v0.110.1","v0.110.0","v0.109.3","v0.109.2","v0.109.1","v0.109.0","v0.108.0","v0.108.0-rc.1","v0.107.0","v0.106.0","v0.105.1","v0.105.0","v0.104.0","v0.104.0-cloud.1","v0.103.1","v0.103.0","v0.102.1","v0.102.0","v0.101.0","v0.101.0-rc.1","v0.100.1","v0.100.0","v0.99.0","v0.98.0","v0.98.0-rc.1","v0.98.0-rc.0","v0.97.1","v0.97.0","v0.97.0-rc.3","v0.97.0-rc.2","v0.97.0-rc.1","v0.96.1","v0.96.0","v0.95.1-cloud.1","v0.95.1","v0.95.0","v0.94.1-cloud.1","v0.94.0","v0.94.1","v0.93.0-cloud.3","v0.93.0-cloud.2","v0.93.0-cloud.1","v0.93.0","v0.93.0-rc.1","v0.93.0-rc.3","v0.93.0-rc.2","v0.92.2","v0.92.1","v0.92.0","v0.91.1","v0.92.0-rc.5","v0.92.0-rc.1","v0.92.0-cloud.1","v0.91.0","v0.90.1","v0.90.0","v0.89.0","v0.88.1","v0.88.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93292.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N"}]}