OVERVIEW CVE-2025-41118 is a credential exposure vulnerability in Pyroscope, an open-source continuous profiling database. The flaw allows attackers to extract the Tencent Cloud Object Storage (COS) secret_key configuration value through the Pyroscope API when the database is configured to use Tencent COS as its storage backend. The vulnerability affects Pyroscope versions prior to 1.15.2, 1.16.1, and 1.17.0. SEVERITY This vulnerability carries a CRITICAL CVSS score of 9.1 with a network-based attack vector, requiring no authentication or user interaction. The attack is trivially exploitable with low complexity, leading to complete compromise of confidentiality and integrity of stored profiling data and cloud storage credentials. Successful exploitation enables attackers to access sensitive configuration secrets that could facilitate further cloud infrastructure compromise. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, as indicated by the vulnerability's absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive Hot List status. The EPSS score of 0.00041 suggests minimal current exploitation probability. However, organizations should prioritize patching as the attack requires only direct API access without authentication, and the exposure of cloud storage credentials poses significant downstream risk regardless of current exploitation activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.16.0CPE match | cpe:2.3:a:grafana:pyroscope:*:*:*:*:*:*:*:* | ||
< 1.15.2CPE matchmatch criteria | cpe:2.3:a:grafana:pyroscope:*:*:*:*:*:*:*:* | ||
1.16.0CPE matchmatch criteria | cpe:2.3:a:grafana:pyroscope:1.16.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.