go package report

Is grafana:loki_datasource safe?

1 known vulnerability, worst severity HIGH.

cvss
7.7
high

severity out of 10

epss
0.44%
low

chance of exploitation in 30 days, 38th percentile of all CVEs

xyz score
3.4
low

CyberXYZ composite out of 10

fig. 01 — CVE-2026-42129, the advisory selected below

// 1 advisories

CVE-2026-42129

HIGH

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resource sandbox and access administrative Loki endpoints (e.g. /config, /services, /ready) to extract sensitive backend configuration and internal service information.

// cvss v3.1 vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None
Affected
>=2.0.0-beta1
Fixed in
not stated
Weakness
CWE-22, Path traversal
Published
2026-06-22, updated 2026-09-21
Sources
NVD
// references

// dependencies

0 direct

Create a free accountfor dependency paths and remediation
// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so go packages are not covered.


Checked 2026-09-22 at 17:34 UTC. The most recent advisory here was published 2026-06-22. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is grafana:loki_datasource safe? go package security report | CyberXYZ