A vulnerability, which was classified as critical , was found in signoz up to 0.130.1 . This affects the function url . Such manipulation leads to sql injection. This vulnerability is traded as CVE-2026-57955 . The attack may be launched remotely. There is no exploit available.