CRE-2025-0030
SQLAlchemy applications using `create_engine()` may fail to connect to a database if the username or password contains special characters (e.g., `@`, `\:`, `/`, `\#`). These characters must be URL\-encoded when included in the database connection string. Failure to encode them leads to parsing errors or incorrect credential usage.
CRE-2025-0031
Django applications may return a \"DisallowedHost\" error when receiving requests with an unrecognized or missing Host header. This typically occurs in production environments where reverse proxies, load balancers, or external clients send requests using an unexpected domain or IP address. Django blocks these requests unless the domain is explicitly listed in `ALLOWED_HOSTS`.
CRE-2025-0032
Loki instances using memcached for caching may emit excessive warning or error logs when the configured`memcached_client` service port name does not match the actual Kubernetes service port. This does not cause a crash or failure, but it results in noisy logs and ineffective caching behavior.
CRE-2025-0034
If the Datadog agent or client libraries do not detect a configured API key, they will skip sending metrics, logs, and events. This results in a silent failure of observability reporting, often visible only through startup log messages.
CRE-2025-0043
Grafana may reject custom or third\-party plugins at runtime if they are not digitally signed. When plugin signature validation is enabled (default since Grafana 8+), unsigned plugins are blocked and logged as validation errors during startup or plugin loading.
CRE-2025-0044
Detects NGINX configuration files that advertise obsolete and cryptographically weak ciphers (RC4\-MD5, RC4\-SHA, DES\-CBC3\-SHA).
CRE-2025-0053
NGINX server is receiving upload requests with bodies that exceed the configured size limits.
CRE-2025-0055
Nginx reports that an upstream server is sending headers that exceed the configured buffer size limits.
CRE-2025-0056
NGINX has reported that the configured worker_connections limit has been reached. This indicates that the web server
CRE-2025-0059
\- Datadog Cluster Agent fails to register its CWS (Container Workload Security) instrumentation webhook when running in `remote_copy` mode without a configured service account.
CRE-2025-0085
Detects SpiceDB schema validation failures that prevent authorization
CRE-2025-0162
Detects critical CUDA out of memory errors in Stable Diffusion WebUI that cause image generation failures and application crashes. This occurs when GPU VRAM is exhausted during model loading or image generation, resulting in complete task failure and potential WebUI instability.
PREQUEL-2025-0093
The aws\-load\-balancer\-controller is unable to translate an Ingress resource into an AWS ALB Listener Rule when the path contains a wildcard (*) and the pathType is set to Prefix.
PREQUEL-2025-0096
Loki ingester encounters \"object too large for cache\" errors when attempting to store log entries
PREQUEL-2025-0097
Loki compactor encounters schema configuration mismatches when it finds index tables in object storage
PREQUEL-2025-0098
Loki distributor encounters \"empty ring\" errors when attempting to send streams to pattern ingesters.
PREQUEL-2025-0099
DataDog Agent encounters \"empty targets meta in director local store\" errors when attempting to
PREQUEL-2025-0100
Grafana Mimir's distributor rejects incoming Prometheus series when the number of label
PREQUEL-2025-0101
Loki ingester reports memcached errors indicating out\-of\-memory conditions while caching