CVE-2026-63094
SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft
CVSS Score
8.1
EPSS Score
0.2%
EPSS Percentile
7th
SigNoz before 0.134.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session tokens from any user on instances configured with Google OAuth, SAML, or OIDC. Attackers can call the unauthenticated sessions context endpoint with a ref parameter pointing to an attacker-controlled host, deliver the resulting crafted login URL to a victim, and receive the victim's access and refresh tokens when they complete SSO authentication.
| CWE | CWE-601 CWE-345 |
| Vendor | signoz |
| Product | signoz |
| Published | Jul 17, 2026 |
| Last Updated | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for signoz signoz
Be the first to know when new high vulnerabilities affecting signoz signoz are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
SigNoz / signoz
0 < 0.134.0
References
github.com: https://github.com/SigNoz/signoz/issues/11746 github.com: https://github.com/SigNoz/signoz/releases/tag/v0.134.0 github.com: https://github.com/SigNoz/signoz/pull/12172 github.com: https://github.com/SigNoz/signoz/commit/253ca7dd7eb4f7a32a694c249eb0d5d0804d5619 vulncheck.com: https://www.vulncheck.com/advisories/signoz-sso-oauth-state-manipulation-session-token-theft
Credits
George Chen