Grafana Loki · Vulnerability Disclosure

Grafana Loki Vulnerability Disclosure

Vulnerability disclosure

Grafana Labs runs one vulnerability disclosure program covering every product, open source and commercial, explicitly naming Grafana, Grafana Cloud, Grafana Enterprise and grafana.com — which includes Grafana Loki and Grafana Cloud Logs. The program is hosted on Intigriti; email reports to a PGP-published address are also accepted.

Grafana Loki runs a coordinated vulnerability disclosure program on Intigriti. A dedicated security contact is published.

CompanyLogsLoggingLog AggregationObservabilityMonitoringOpen-SourceLogQLOpenTelemetryTelemetryKubernetesCloud-Native
Program: Intigriti

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
emailsecurity@grafana.com
Contact
email_noteAccepted, but email reports are not eligible for the Hall of Fame. The address accepts vulnerability reports only; other security questions go to Grafana Labs support.
Contact
pgptrue
Contact
pgp_fingerprint225E 6A9B BB15 A37E 95EB 6312 C66A 51CC B44C 27E0

Source

Vulnerability Disclosure

grafana-loki-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-27'
method: searched
source: https://github.com/grafana/.github/blob/main/SECURITY.md
name: Grafana Loki vulnerability disclosure
description: >-
  Grafana Labs runs one vulnerability disclosure program covering every product, open source and
  commercial, explicitly naming Grafana, Grafana Cloud, Grafana Enterprise and grafana.com — which
  includes Grafana Loki and Grafana Cloud Logs. The program is hosted on Intigriti; email reports to
  a PGP-published address are also accepted.
program:
  type: vulnerability-disclosure-program
  name: Grafana Labs Vulnerability Disclosure Program (VDP)
  platform: Intigriti
  url: https://app.intigriti.com/programs/grafana/grafanalabs/detail
  url_status: 200
  bounty: false
  bounty_note: '"Please note that we do not offer bounties for any vulnerability report."'
  hall_of_fame: true
  hall_of_fame_note: 'Only reports submitted via Intigriti are eligible for the Hall of Fame.'
  account_required: true
  account_note: 'An Intigriti account is required to submit a report.'
contact:
  email: security@grafana.com
  email_note: >-
    Accepted, but email reports are not eligible for the Hall of Fame. The address accepts
    vulnerability reports only; other security questions go to Grafana Labs support.
  pgp: true
  pgp_fingerprint: '225E 6A9B BB15 A37E 95EB 6312 C66A 51CC B44C 27E0'
policy:
  url: https://github.com/grafana/.github/blob/main/SECURITY.md
  scope: >-
    "Any of Grafana Labs' open source and commercial products (including but not limited to Grafana,
    Grafana Cloud, Grafana Enterprise, and grafana.com) are in scope."
  coordinated_disclosure: true
  disclosure_statement: >-
    "We ask you to not disclose the vulnerability before it have been fixed and announced, unless you
    received a response from the Grafana Labs security team that you can do so."
  in_scope_products_named: [Grafana, Grafana Cloud, Grafana Enterprise, grafana.com]
  loki_covered: true
  loki_covered_reason: >-
    Loki is a Grafana Labs open source product and Grafana Cloud Logs is a Grafana Cloud service;
    both fall inside the stated scope.
advisories:
  url: https://grafana.com/security/
  url_status: 200
  note: >-
    Grafana Labs publishes a Security Advisories index and a Hall of Fame at grafana.com/security/.
    Loki CVEs are additionally published as GitHub Security Advisories on grafana/loki.
  github_advisories: https://github.com/grafana/loki/security/advisories
security_tooling_in_repo:
  note: >-
    The grafana/loki repository runs published supply-chain and vulnerability workflows in CI, which
    is corroborating evidence that the disclosure program is backed by real practice.
  workflows: [govulncheck.yml, snyk.yml, secret-scanning.yml, syft-sbom-ci.yml, zizmor.yml]
security_txt:
  published: false
  probed:
    - {url: 'https://grafana.com/.well-known/security.txt', status: 404}
    - {url: 'https://mcp.grafana.com/.well-known/security.txt', status: 404}
    - {url: 'https://logs-prod-008.grafana.net/.well-known/security.txt', status: 404}
  note: >-
    Grafana Labs runs a full VDP but serves no RFC 9116 security.txt on any host probed. That is the
    one gap in an otherwise complete disclosure posture, and it is cheap for the provider to close.
checked: '2026-08-27'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/grafana-loki-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.