#VU120880 Missing Authorization in Pyroscope - CVE-2025-41118
Published: January 2, 2026
Pyroscope
Grafana Labs
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the Pyroscope API may return the secret_key configuration value if the database is configured to use Tencent COS as the storage backend. A remote non-authenticated attacker can gain unauthorized access to the database.