SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session… (CVE-2026-63094)
SigNoz versions through 0.133.0 have an open redirect vulnerability in the Single Sign-On (SSO) authentication flow. This flaw allows unauthenticated attackers to steal session tokens from users on instances configured with Google OAuth, SAML, or OIDC. Attackers exploit this by crafting a login URL with a redirect parameter pointing to a malicious host and tricking victims into completing the SSO authentication, thereby capturing their access and refresh tokens.
AI Analysis
Technical Summary
An open redirect vulnerability exists in SigNoz versions up to 0.133.0 within the SSO authentication flow. The vulnerability enables unauthenticated attackers to abuse the 'ref' parameter in the unauthenticated sessions context endpoint to redirect victims to attacker-controlled hosts. When victims complete SSO authentication via Google OAuth, SAML, or OIDC, attackers can intercept their access and refresh tokens, effectively compromising user sessions. This vulnerability is tracked as CVE-2026-63094 and is categorized under CWE-345 (Insufficient Verification of Data Authenticity).
Potential Impact
Successful exploitation allows attackers to steal session tokens from any user on affected SigNoz instances configured with supported SSO providers. This leads to unauthorized access to user accounts and potentially sensitive data. The vulnerability affects the confidentiality and integrity of user sessions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using vulnerable versions in production environments or restrict access to trusted users only. Monitor vendor channels for updates regarding patches or official mitigations.
SigNoz through 0.133.0 contains an open redirect vulnerability in the SSO authentication flow that allows unauthenticated attackers to steal session… (CVE-2026-63094)
Description
SigNoz versions through 0.133.0 have an open redirect vulnerability in the Single Sign-On (SSO) authentication flow. This flaw allows unauthenticated attackers to steal session tokens from users on instances configured with Google OAuth, SAML, or OIDC. Attackers exploit this by crafting a login URL with a redirect parameter pointing to a malicious host and tricking victims into completing the SSO authentication, thereby capturing their access and refresh tokens.
CVSS v4.0
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
An open redirect vulnerability exists in SigNoz versions up to 0.133.0 within the SSO authentication flow. The vulnerability enables unauthenticated attackers to abuse the 'ref' parameter in the unauthenticated sessions context endpoint to redirect victims to attacker-controlled hosts. When victims complete SSO authentication via Google OAuth, SAML, or OIDC, attackers can intercept their access and refresh tokens, effectively compromising user sessions. This vulnerability is tracked as CVE-2026-63094 and is categorized under CWE-345 (Insufficient Verification of Data Authenticity).
Potential Impact
Successful exploitation allows attackers to steal session tokens from any user on affected SigNoz instances configured with supported SSO providers. This leads to unauthorized access to user accounts and potentially sensitive data. The vulnerability affects the confidentiality and integrity of user sessions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid using vulnerable versions in production environments or restrict access to trusted users only. Monitor vendor channels for updates regarding patches or official mitigations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-xmw5-w4c2-cp2g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-63094"]
- Ecosystems
- []
- Database Specific Severity
- HIGH
- Cvss Version
- 4.0
Threat ID: 6a5fd1601010f89cc21ca7f8
Added to database: 07/21/2026, 20:06:56 UTC
Last enriched: 07/21/2026, 20:20:06 UTC
Last updated: 07/21/2026, 20:57:08 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.