CVE-2026-21729Disclosed before NVD
Loki detected_fields query limits results in unbounded memory allocation
📋 Description
The Loki detected_fields endpoint allocates 2*limit elements in slices and maps based on the user-supplied limit query parameter, regardless of actual result count. A massive limit value (e.g. 600000000) allocates 20-30 GiB even with zero matching results, causing OOM, resulting in denial of service.
🎯 Affected products1
- Loki