Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-41118
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-41118 is a credential exposure vulnerability in Grafana Pyroscope, an open-source continuous profiling database, that allows unauthenticated attackers to extract the Tencent Cloud Object Storage (COS) secret_key configuration value via the Pyroscope API. The vulnerability was published on April 15, 2026, and was reported by Théo Cusnir through Grafana's bug bounty program. Affected versions include all Pyroscope releases before 1.15.2, and version 1.16.0 specifically; versions 1.15.2+, 1.16.1+, and all 1.17.x releases are patched. It carries a CVSS v3.1 base score of 9.1 (Critical) (GitHub Advisory, Grafana Advisory).

Technical details

The root cause is classified as CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor), meaning the Pyroscope API endpoint does not properly restrict access to sensitive configuration data (GitHub Advisory). When Pyroscope is configured to use Tencent COS as its storage backend, the secret_key credential is exposed through the API without requiring authentication, privileges, or user interaction. The attack vector is network-based with low complexity, making it trivially exploitable by any party with direct network access to the Pyroscope API (GitHub Advisory, Grafana Advisory). The sole precondition is that the Pyroscope instance must be configured to use Tencent COS as its storage backend.

Impact

Successful exploitation allows an unauthenticated attacker to retrieve the Tencent COS secret_key, which is a cloud storage credential granting access to the configured COS bucket. With this credential, an attacker could access, modify, or delete profiling data stored in the COS backend, compromising both confidentiality and integrity of stored data. There is no direct availability impact to the Pyroscope service itself, but the exposure of cloud credentials could enable broader compromise of the associated Tencent Cloud environment and any data stored therein (GitHub Advisory, Grafana Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.016% (4th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Despite the low exploitation probability, the unauthenticated, network-accessible nature of the flaw makes it a high-priority patching target for any internet-exposed Pyroscope instances using Tencent COS (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Pyroscope instances using tools like Shodan or Censys, or by scanning for the default Pyroscope API port. Confirm the version is below 1.15.2 or equals 1.16.0.
  2. Determine storage backend: Query the Pyroscope API or review any exposed configuration endpoints to confirm the instance is configured to use Tencent COS as its storage backend.
  3. Extract the secret_key: Send an unauthenticated HTTP request to the relevant Pyroscope API endpoint that exposes configuration data. No credentials, special headers, or user interaction are required.
  4. Leverage the credential: Use the extracted Tencent COS secret_key along with the associated secret_id (if also obtainable) to authenticate to the Tencent Cloud COS API, enabling read, write, or delete operations on the profiling data bucket (GitHub Advisory, Grafana Advisory).

Indicators of compromise

  • Network: Unexpected or anomalous unauthenticated HTTP requests to Pyroscope API configuration or status endpoints from external or untrusted IP addresses; outbound connections from the Pyroscope host to Tencent COS endpoints from unusual source IPs.
  • Logs: Pyroscope API access logs showing repeated or unusual GET requests to configuration-related endpoints from unknown clients; Tencent COS access logs showing API calls using the secret_key from IP addresses not associated with the Pyroscope server.
  • Cloud Storage: Unexpected access, modification, or deletion events in the Tencent COS bucket associated with Pyroscope, particularly from unfamiliar IP addresses or at unusual times.

Mitigation and workarounds

Grafana has released patched versions: 1.15.2 (for 1.15.x branch), 1.16.1 (for 1.16.x branch), and all 1.17.x releases include the fix. Users should upgrade to the appropriate patched version as the primary remediation. As an immediate workaround, restrict network access to the Pyroscope API using firewall rules or network policies so it is only reachable by trusted internal systems or users, and avoid exposing Pyroscope instances to the public internet. Additionally, rotating the Tencent COS secret_key is recommended for any instances that may have been exposed (GitHub Advisory, Grafana Advisory).

Community reactions

The vulnerability was responsibly disclosed by Théo Cusnir via Grafana's bug bounty program and acknowledged in the official Grafana security advisory. The CISA vulnerability bulletin for the week of April 13, 2026 referenced this CVE, indicating it received standard government tracking attention. Social media activity was limited, with brief mentions on Bluesky and Mastodon, and no significant community controversy or widespread media coverage was observed (Grafana Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Affected

RHEL 9

Not Affected

RHEL 10

Not Affected

SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-91782LOW1.9
  • NixOS logoNixOS
  • gcc10-binutils
NoYesSep 15, 2026
CVE-2026-91781LOW1.9
  • NixOS logoNixOS
  • binutils
NoYesSep 15, 2026
CVE-2026-91780LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-91779LOW1.9
  • NixOS logoNixOS
  • binutils
NoNoSep 15, 2026
CVE-2026-90831LOW1.9
  • NixOS logoNixOS
  • gcc-toolset-16-binutils.src
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management