Uncontrolled Memory Allocation in Loki - CVE-2026-21729
Published: July 16, 2026 / Updated: July 24, 2026
Loki
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in the detected_fields endpoint when processing a user-supplied limit query parameter. A remote attacker can send a specially crafted request with a massive limit value to cause a denial of service.
The issue can trigger out-of-memory conditions even when there are no matching results.