THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-41118 (CRITICAL 9.1) — Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuratio

[NVD] CVE-2025-41118 (CRITICAL 9.1) — Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuratio

lownvdPublished 2026-04-15

CVE-2025-41118 CVSS: 9.1 CRITICAL Published: 2026-04-15T20:16:32.933

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS).

If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API.

To exploit this v

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-41118