{
  "threat_severity" : "Important",
  "public_date" : "2026-04-15T19:15:17Z",
  "bugzilla" : {
    "description" : "pyroscope: sensitive COS SecretKey exposed in plaintext via configuration API due to missing type protection",
    "id" : "2458796",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2458796"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-201",
  "details" : [ "Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).\nIf the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API.\nTo exploit this vulnerability, an attacker needs direct access to the Pyroscope API. We highly recommend limiting the public internet exposure of all our databases, such that they are only accessible by trusted users or internal systems.\nThis vulnerability is fixed in versions:\n1.15.x: 1.15.2 and above.\n1.16.x: 1.16.1 and above.\n1.17.x: 1.17.0 and above (i.e. all versions).\nThanks to Théo Cusnir for reporting this vulnerability to us via our bug bounty program.", "A flaw was found in Pyroscope. When Tencent Cloud Object Storage (COS) is configured as the storage backend, an attacker with access to the Pyroscope API can extract the `secret_key` value in plaintext. This issue leads to sensitive information disclosure." ],
  "statement" : "This flaw allows an attacker with direct access to the Pyroscope API to extract the Tencent Cloud Object Storage (COS) `secret_key` in plaintext when COS is configured as the storage backend. Due to this reason, this vulnerability has been rated with an important severity.",
  "affected_release" : [ {
    "product_name" : "Multicluster Global Hub 1.7.1",
    "release_date" : "2026-06-08T00:00:00Z",
    "advisory" : "RHSA-2026:24503",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub:1.7::el9",
    "package" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel9:1779925273"
  } ],
  "package_state" : [ {
    "product_name" : "Multicluster Global Hub",
    "fix_state" : "Not affected",
    "package_name" : "multicluster-globalhub/multicluster-globalhub-grafana-rhel8",
    "cpe" : "cpe:/a:redhat:multicluster_globalhub"
  }, {
    "product_name" : "Red Hat Advanced Cluster Management for Kubernetes 2",
    "fix_state" : "Affected",
    "package_name" : "rhacm2/acm-grafana-rhel9",
    "cpe" : "cpe:/a:redhat:acm:2"
  }, {
    "product_name" : "Red Hat Ceph Storage 5",
    "fix_state" : "Not affected",
    "package_name" : "rhceph/rhceph-5-dashboard-rhel8",
    "cpe" : "cpe:/a:redhat:ceph_storage:5"
  }, {
    "product_name" : "Red Hat Ceph Storage 6",
    "fix_state" : "Fix deferred",
    "package_name" : "rhceph/rhceph-6-dashboard-rhel9",
    "cpe" : "cpe:/a:redhat:ceph_storage:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Not affected",
    "package_name" : "grafana",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-41118\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-41118\nhttps://grafana.com/security/security-advisories/cve-2025-41118" ],
  "name" : "CVE-2025-41118",
  "mitigation" : {
    "value" : "To mitigate this vulnerability, limit network exposure of the Pyroscope API so it is only accessible by trusted users on the internal network.",
    "lang" : "en:us"
  },
  "csaw" : false
}