github.com/cortexproject/cortex
A horizontally scalable, highly available, multi-tenant, long term Prometheus.
Activity
- Latest release
- Jun 05, 2026
- Total releases
- 50
- Cadence
- ~23 days
- Last 12 months
- 4
Reach
- Stars
- 5.8k
Details
- First release
- Aug 07, 2019
| Version | Released | |
|---|---|---|
v1.21.1
minor
|
v1.21.1
minor
Dependencies (87)
+ 79 more |
|
v1.21.1-rc.0
pre
|
v1.21.1-rc.0
pre
Dependencies (87)
+ 79 more |
|
v1.21.0-rc.1
pre
|
v1.21.0-rc.1
pre
Dependencies (87)
+ 79 more |
|
v1.20.0-rc.1
pre
|
v1.20.0-rc.1
pre
Dependencies (86)
+ 78 more |
|
v1.19.0-rc.1
pre
|
v1.19.0-rc.1
pre
Dependencies (79)
+ 71 more |
|
v1.18.0-rc.0
pre
|
v1.18.0-rc.0
pre
Dependencies (77)
+ 69 more |
|
v1.17.1
minor
|
v1.17.1
minor
Dependencies (77)
+ 69 more |
|
v1.17.0-rc.1
pre
|
v1.17.0-rc.1
pre
Dependencies (77)
+ 69 more |
|
v1.16.0
minor
|
v1.16.0
minor
Dependencies (73)
+ 65 more |
|
v1.16.0-rc.0
pre
|
v1.16.0-rc.0
pre
Dependencies (73)
+ 65 more |
|
v1.15.3
patch
|
v1.15.3
patch
Dependencies (72)
+ 64 more |
|
v1.15.2
patch
|
v1.15.2
patch
Dependencies (72)
+ 64 more |
|
v1.15.0
minor
|
v1.15.0
minor
Dependencies (72)
+ 64 more |
|
v1.15.0-rc.2
pre
|
v1.15.0-rc.2
pre
Dependencies (72)
+ 64 more |
|
v1.15.0-rc.1
pre
|
v1.15.0-rc.1
pre
Dependencies (72)
+ 64 more |
|
v1.15.0-rc.0
pre
|
v1.15.0-rc.0
pre
Dependencies (72)
+ 64 more |
|
v1.13.2
patch
|
v1.13.2
patch
Dependencies (68)
+ 60 more |
|
v1.13.0
minor
1 CVE
CVE-2022-23536
GO-2022-1175
GHSA-cq2g-pw6q-hf7j
Dec 22, 2022
Exposure of local files in github.com/cortexproject/cortex A malicious actor could remotely read local files by submitting to the Alertmanager Set Configuration API maliciously crafted inputs. Only users of the Alertmanager service where "-experimental.alertmanager.enable-api" or "enable_api: true" is configured are affected. Fixed in
1.13.2
1.14.1
References Updated May 20, 2024 · Source: OSV.dev |
v1.13.0
minor
Dependencies (68)
+ 60 more |
|
v1.12.0-rc.0
pre
|
v1.12.0-rc.0
pre
Dependencies (67)
+ 59 more |
|
v1.11.1
patch
|
v1.11.1
patch
Dependencies (60)
+ 52 more |
|
v1.11.0
minor
|
v1.11.0
minor
Dependencies (60)
+ 52 more |
|
v1.11.0-rc.1
pre
|
v1.11.0-rc.1
pre
Dependencies (60)
+ 52 more |
|
v1.10.0
minor
|
v1.10.0
minor
Dependencies (67)
+ 59 more |
|
v1.10.0-rc.1
pre
|
v1.10.0-rc.1
pre
Dependencies (67)
+ 59 more |
|
v1.10.0-rc.0
pre
|
v1.10.0-rc.0
pre
Dependencies (67)
+ 59 more |
|
v1.9.0-rc.0
pre
1 CVE
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.9.0-rc.0
pre
Dependencies (65)
+ 57 more |
|
v1.8.1
minor
1 CVE
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.8.1
minor
Dependencies (65)
+ 57 more |
|
v1.8.0-rc.1
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.8.0-rc.1
pre
Dependencies (65)
+ 57 more |
|
v1.8.0-rc.0
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.8.0-rc.0
pre
Dependencies (65)
+ 57 more |
|
v1.7.0-rc.2
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.7.0-rc.2
pre
Dependencies (63)
+ 55 more |
|
v1.7.0-rc.0
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.7.0-rc.0
pre
Dependencies (63)
+ 55 more |
|
v1.5.0-rc.1
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.5.0-rc.1
pre
Dependencies (63)
+ 55 more |
|
v1.5.0-rc.0
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.5.0-rc.0
pre
Dependencies (63)
+ 55 more |
|
v1.4.0
minor
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.0
minor
Dependencies (63)
+ 55 more |
|
v1.4.0-rc.1
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.0-rc.1
pre
Dependencies (63)
+ 55 more |
|
v1.4.0-rc.0
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.4.0-rc.0
pre
Dependencies (63)
+ 55 more |
|
v1.3.0-rc.2
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.0-rc.2
pre
Dependencies (61)
+ 53 more |
|
v1.3.0-rc.1
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.3.0-rc.1
pre
Dependencies (61)
+ 53 more |
|
v1.2.0
minor
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.0
minor
Dependencies (60)
+ 52 more |
|
v1.2.0-rc.1
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.0-rc.1
pre
Dependencies (60)
+ 52 more |
|
v1.1.0
minor
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.0
minor
Dependencies (60)
+ 52 more |
|
v1.1.0-rc.0
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.0-rc.0
pre
Dependencies (60)
+ 52 more |
|
v1.0.1
major
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.1
major
Dependencies (57)
+ 49 more |
|
v1.0.0-rc.0
pre
2 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.0-rc.0
pre
Dependencies (57)
+ 49 more |
|
v0.5.0-rc.0
pre
3 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41265
GHSA-vw7g-3cc7-7rmh
GO-2024-3036
Aug 01, 2024
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
High
Network
Low
None
None
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. References Updated Dec 20, 2025 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v0.5.0-rc.0
pre
Dependencies (54)
+ 46 more |
|
v0.4.0
minor
3 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41265
GHSA-vw7g-3cc7-7rmh
GO-2024-3036
Aug 01, 2024
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
High
Network
Low
None
None
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. References Updated Dec 20, 2025 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.0
minor
Dependencies (50)
+ 42 more |
|
v0.4.0-rc.0
pre
3 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41265
GHSA-vw7g-3cc7-7rmh
GO-2024-3036
Aug 01, 2024
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
High
Network
Low
None
None
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. References Updated Dec 20, 2025 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v0.4.0-rc.0
pre
Dependencies (50)
+ 42 more |
|
v0.2.0
minor
3 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41265
GHSA-vw7g-3cc7-7rmh
GO-2024-3036
Aug 01, 2024
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
High
Network
Low
None
None
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. References Updated Dec 20, 2025 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v0.2.0
minor
Dependencies (44)
+ 36 more |
|
v0.2.0-rc.0
pre
3 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41265
GHSA-vw7g-3cc7-7rmh
GO-2024-3036
Aug 01, 2024
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
High
Network
Low
None
None
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. References Updated Dec 20, 2025 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v0.2.0-rc.0
pre
Dependencies (44)
+ 36 more |
|
v0.1.0
initial
3 CVEs
CVE-2021-31232
GO-2022-0915
GHSA-m45g-f45x-vv22
Aug 21, 2024
Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Improper input validation in CNCF Cortex in github.com/cortexproject/cortex Fixed in
1.8.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-41265
GHSA-vw7g-3cc7-7rmh
GO-2024-3036
Aug 01, 2024
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
High
Network
Low
None
None
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function. References Updated Dec 20, 2025 · Source: OSV.dev
CVE-2021-36157
GHSA-jphm-g89m-v42p
Sep 02, 2021
Path traversal in Grafana Cortex
Medium
An issue was discovered in Grafana Cortex through 1.9.0. The header value X-Scope-OrgID is used to construct file paths for rules files, and if crafted to conduct directory traversal such as ae ../../sensitive/path/in/deployment pathname, then Cortex will attempt to parse a rules file at that location and include some of the contents in the error message. (Other Cortex API requests can also be sent a malicious OrgID header, e.g., tricking the ingester into writing metrics to a different location, but the effect is nuisance rather than information disclosure.) References Updated Nov 08, 2023 · Source: OSV.dev |
v0.1.0
initial
Dependencies (46)
+ 38 more |