Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-41118

35
FAUCET Score

OVERVIEW CVE-2025-41118 is a credential exposure vulnerability in Pyroscope, an open-source continuous profiling database. The flaw allows attackers to extract the Tencent Cloud Object Storage (COS) secret_key configuration value through the Pyroscope API when the database is configured to use Tencent COS as its storage backend. The vulnerability affects Pyroscope versions prior to 1.15.2, 1.16.1, and 1.17.0. SEVERITY This vulnerability carries a CRITICAL CVSS score of 9.1 with a network-based attack vector, requiring no authentication or user interaction. The attack is trivially exploitable with low complexity, leading to complete compromise of confidentiality and integrity of stored profiling data and cloud storage credentials. Successful exploitation enables attackers to access sensitive configuration secrets that could facilitate further cloud infrastructure compromise. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive Hot List status. The EPSS score of 0.00041 suggests minimal current exploitation probability. However, organizations should prioritize patching as the attack requires only direct API access without authentication, and the exposure of cloud storage credentials poses significant downstream risk regardless of current exploitation activity.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, < 1.16.0CPE match
cpe:2.3:a:grafana:pyroscope:*:*:*:*:*:*:*:*
< 1.15.2CPE matchmatch criteria
cpe:2.3:a:grafana:pyroscope:*:*:*:*:*:*:*:*
1.16.0CPE matchmatch criteria
cpe:2.3:a:grafana:pyroscope:1.16.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 10th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

gopatch availablevia ghsa
Product: github.com/grafana/pyroscopeFixed in: 1.15.2
gopatch availablevia ghsa
Product: github.com/grafana/pyroscopeFixed in: 1.16.1

Vendor Advisories (1)

goGHSA-m9hq-h476-h2g8critical

Pyroscope Exposes Storage Secret

Apr 15, 2026

References

access.redhat.com / errata/RHSA-2026:24503
access.redhat.com / security/cve/CVE-2025-41118
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-41118.json
grafana.com / security/security-advisories/cve-2025-41118
Vendor Advisory