Junglewise Threat Intelligence

CVE-2025-41118: Grafana Pyroscope information disclosure in Tencent COS configuration API

CVE-2025-41118 · Severity: critical · CVSS 9.1 · Published 2026-04-15

Technologies: Red Hat Multicluster Global Hub. Vendors: Red Hat, Go, Grafana Labs.

Executive brief

Pyroscope, an open-source tool used for monitoring application performance, contains a security flaw when using Tencent Cloud Object Storage (COS) as its storage backend. An attacker with access to the Pyroscope API can retrieve the secret key used to access the cloud storage. This could allow an unauthorized party to access, modify, or delete sensitive performance data stored in the cloud.

Technical details

A vulnerability in Grafana Pyroscope (CWE-201/CWE-732) occurs when the database is configured to use Tencent Cloud Object Storage (COS) as a backend. The application fails to protect the 'secret_key' configuration value, exposing it in plaintext through the Pyroscope configuration API. An unauthenticated attacker with network access to the API can extract these credentials. This issue is fixed in versions 1.15.2, 1.16.1, and all versions from 1.17.0 onwards. Red Hat products incorporating Pyroscope, such as Multicluster Global Hub and Ceph Storage 6, are also impacted.

Affected products

  • Grafana Labs Pyroscope < 1.15.2, 1.16.0
  • Red Hat Multicluster Global Hub 1.7.1 1.7::el9
  • Red Hat Red Hat Advanced Cluster Management for Kubernetes 2 2
  • Red Hat Red Hat Ceph Storage 6 6

Timeline

  • 2025-01-01: disclosed: Initial release date listed in Red Hat VEX
  • 2026-01-02: advisory: Grafana Labs advisory published
  • 2026-04-15: advisory: NVD publication date
  • 2026-06-08: patched: Red Hat security update issued

References

Related threats