Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21729

Опубликовано: 16 июл. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

A flaw was found in Loki. A remote attacker can exploit this vulnerability by sending specially crafted queries with large limits, leading to excessive memory allocation. This can cause a Denial of Service (DoS) by impacting the availability of the Loki service.

Меры по смягчению последствий

To mitigate this issue, configure the Loki service to enforce stricter limits on query parameters. This can prevent excessive memory allocations caused by large queries. Refer to the Loki documentation for details on configuring query limits, such as maximum series or query length. A restart of the Loki service is required for any configuration changes to take effect, which may temporarily impact service availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imagesloki3.6Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2501250Loki: Loki: Denial of Service via large limit queries

EPSS

Процентиль: 38%
0.0046
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

CVSS3: 7.5
github
2 месяца назад

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость компонента Query Engine системы для агрегации и хранения логов Loki, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 38%
0.0046
Низкий

7.5 High

CVSS3