loki-3.6-promtail

Direct Vulnerabilities

Known vulnerabilities in the loki-3.6-promtail package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-56852

<3.6.12-r2
  • L
GHSA-hrxh-6v49-42gf

<3.6.12-r2
  • L
CVE-2026-46600

<3.6.12-r2
  • L
CVE-2026-39822

<3.6.12-r1
  • L
CVE-2026-42505

<3.6.12-r1
  • L
Uncontrolled Memory Allocation

<3.6.12-r0
  • H
Symlink Following

*
  • L
Uncontrolled Search Path Element

*
  • L
CVE-2026-2303

<3.6.11-r0
  • H
Off-by-one Error

*
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<3.6.11-r1
  • L
Deserialization of Untrusted Data

<3.6.11-r1
  • L
CVE-2026-42507

<3.6.11-r1
  • L
CVE-2026-39824

<3.6.11-r1
  • L
CVE-2026-42504

<3.6.11-r1
  • L
Missing Authorization

<3.6.11-r1
  • L
Improper Certificate Validation

<3.6.11-r1
  • L
Resource Exhaustion

<3.6.11-r1
  • L
Out-of-Bounds

<3.6.11-r1
  • L
Missing Authorization

<3.6.11-r1
  • L
Improper Certificate Validation

<3.6.11-r1
  • L
Improper Certificate Validation

<3.6.11-r1
  • L
CVE-2026-46595

<3.6.11-r1
  • L
CVE-2026-27145

<3.6.11-r1
  • L
Integer Overflow or Wraparound

<3.6.11-r1
  • L
Improper Verification of Cryptographic Signature

<3.6.11-r1
  • L
CVE-2026-46598

<3.6.11-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<3.6.11-r1
  • L
Incorrect Type Conversion or Cast

<3.6.11-r1
  • L
Improper Restriction of Rendered UI Layers or Frames

<3.6.11-r1
  • L
Cross-site Scripting (XSS)

<3.6.11-r1
  • L
CVE-2026-39821

<3.6.11-r1
  • L
Use of a Broken or Risky Cryptographic Algorithm

<3.6.11-r0
  • L
Improper Restriction of Rendered UI Layers or Frames

<3.6.11-r1
  • M
Use of a Broken or Risky Cryptographic Algorithm

<3.6.11-r0
  • M
Cross-site Scripting (XSS)

<3.6.12-r0
  • L
Information Exposure

<3.6.12-r0
  • L
Resource Exhaustion

<3.6.12-r0
  • H
Allocation of Resources Without Limits or Throttling

<3.6.10-r3
  • L
CVE-2026-42501

<3.6.10-r3
  • M
Out-of-bounds Write

<3.6.10-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<3.6.10-r3
  • M
Link Following

<3.6.10-r3
  • L
Improper Encoding or Escaping of Output

<3.6.10-r3
  • H
Double Free

<3.6.10-r3
  • L
CVE-2026-39825

<3.6.10-r3
  • L
Cross-site Scripting (XSS)

<3.6.10-r3
  • L
CVE-2026-42499

<3.6.10-r3
  • H
NULL Pointer Dereference

<3.6.10-r3
  • H
Authentication Bypass

*
  • L
Uncontrolled Memory Allocation

<3.6.11-r0
  • M
Cross-site Scripting (XSS)

<3.6.11-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.6.11-r0
  • C
CVE-2026-27143

<3.6.10-r2
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<3.6.10-r2
  • L
CVE-2026-21726

<3.6.4-r0
  • L
CVE-2026-32280

<3.6.10-r2
  • M
Cross-site Scripting (XSS)

<3.6.10-r2
  • M
Link Following

<3.6.10-r2
  • H
Improper Certificate Validation

<3.6.10-r2
  • H
Improper Certificate Validation

<3.6.10-r2
  • H
Allocation of Resources Without Limits or Throttling

<3.6.10-r2
  • M
Allocation of Resources Without Limits or Throttling

<3.6.10-r2
  • H
Incorrect Authorization

<3.6.10-r2
  • L
Uncaught Exception

<3.6.10-r1
  • L
Improper Authorization

<3.6.7-r3
  • L
GHSA-6g7g-w4f8-9c9x

<3.6.7-r3
  • L
Improper Certificate Validation

<3.6.7-r2
  • L
Cross-site Scripting (XSS)

<3.6.7-r2
  • L
Improper Certificate Validation

<3.6.7-r2
  • L
Directory Traversal

<3.6.7-r2
  • L
Direct Request ('Forced Browsing')

<3.6.7-r2
  • L
Untrusted Search Path

<3.6.7-r1
  • L
Improper Initialization

<3.6.6-r1
  • L
CVE-2025-61732

<3.6.5-r0
  • C
CVE-2025-68121

<3.6.5-r0
  • L
CVE-2025-61731

<3.6.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.6.4-r0
  • L
Allocation of Resources Without Limits or Throttling

<3.6.4-r0
  • L
Out-of-bounds Write

<3.6.4-r0
  • L
CVE-2025-61730

<3.6.4-r0
  • L
Improper Certificate Validation

<3.6.2-r1
  • L
Improper Certificate Validation

<3.6.2-r1