generated: '2026-08-27' method: searched source: https://github.com/grafana/.github/blob/main/SECURITY.md name: Grafana Loki vulnerability disclosure description: >- Grafana Labs runs one vulnerability disclosure program covering every product, open source and commercial, explicitly naming Grafana, Grafana Cloud, Grafana Enterprise and grafana.com — which includes Grafana Loki and Grafana Cloud Logs. The program is hosted on Intigriti; email reports to a PGP-published address are also accepted. program: type: vulnerability-disclosure-program name: Grafana Labs Vulnerability Disclosure Program (VDP) platform: Intigriti url: https://app.intigriti.com/programs/grafana/grafanalabs/detail url_status: 200 bounty: false bounty_note: '"Please note that we do not offer bounties for any vulnerability report."' hall_of_fame: true hall_of_fame_note: 'Only reports submitted via Intigriti are eligible for the Hall of Fame.' account_required: true account_note: 'An Intigriti account is required to submit a report.' contact: email: security@grafana.com email_note: >- Accepted, but email reports are not eligible for the Hall of Fame. The address accepts vulnerability reports only; other security questions go to Grafana Labs support. pgp: true pgp_fingerprint: '225E 6A9B BB15 A37E 95EB 6312 C66A 51CC B44C 27E0' policy: url: https://github.com/grafana/.github/blob/main/SECURITY.md scope: >- "Any of Grafana Labs' open source and commercial products (including but not limited to Grafana, Grafana Cloud, Grafana Enterprise, and grafana.com) are in scope." coordinated_disclosure: true disclosure_statement: >- "We ask you to not disclose the vulnerability before it have been fixed and announced, unless you received a response from the Grafana Labs security team that you can do so." in_scope_products_named: [Grafana, Grafana Cloud, Grafana Enterprise, grafana.com] loki_covered: true loki_covered_reason: >- Loki is a Grafana Labs open source product and Grafana Cloud Logs is a Grafana Cloud service; both fall inside the stated scope. advisories: url: https://grafana.com/security/ url_status: 200 note: >- Grafana Labs publishes a Security Advisories index and a Hall of Fame at grafana.com/security/. Loki CVEs are additionally published as GitHub Security Advisories on grafana/loki. github_advisories: https://github.com/grafana/loki/security/advisories security_tooling_in_repo: note: >- The grafana/loki repository runs published supply-chain and vulnerability workflows in CI, which is corroborating evidence that the disclosure program is backed by real practice. workflows: [govulncheck.yml, snyk.yml, secret-scanning.yml, syft-sbom-ci.yml, zizmor.yml] security_txt: published: false probed: - {url: 'https://grafana.com/.well-known/security.txt', status: 404} - {url: 'https://mcp.grafana.com/.well-known/security.txt', status: 404} - {url: 'https://logs-prod-008.grafana.net/.well-known/security.txt', status: 404} note: >- Grafana Labs runs a full VDP but serves no RFC 9116 security.txt on any host probed. That is the one gap in an otherwise complete disclosure posture, and it is cheap for the provider to close. checked: '2026-08-27'