Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2026-8609
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually e…
Grafana
11.6.15 / 12.2.9+
MEDIUM 5.4
CVE-2026-8595
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the bro…
Grafana
12.4.4 / 13.0.2+
HIGH 7.5
CVE-2026-33382
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send ver…
Grafana
11.6.15 / 12.2.9+
HIGH 7.5
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor…
Grafana
after 13.0.1
MEDIUM 5.4
CVE-2026-9029
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The …
Grafana
Mitigation only
HIGH 7.7
CVE-2026-42129
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive back…
Loki Datasource
Mitigation only
HIGH 8.1
CVE-2026-28381
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files…
Snowflake
after 1.14.12
MEDIUM 6.5
CVE-2026-27878
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting …
Tempo
2.8.4 / 2.9.2+
HIGH 8.8
CVE-2026-11769
We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation…
Grafana Operator
5.24.0+
HIGH 8.1
CVE-2026-33381
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The …
Grafana
11.6.14 / 12.2.8+
HIGH 7.4
CVE-2026-33376
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to m…
Grafana
11.6.14 / 12.2.8+
HIGH 7.1
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t…
Grafana
11.6.14 / 12.2.8+
MEDIUM 6.5
CVE-2026-28380
Any Editor could delete any snapshot, even if they have no access to read or write them.
Grafana
11.6.14 / 12.2.8+
MEDIUM 6.5
CVE-2026-28383
A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authentic…
Grafana
11.6.14 / 12.2.8+
MEDIUM 6.5
CVE-2026-33378
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-resta…
Grafana
11.6.14 / 12.2.8+
MEDIUM 6.5
CVE-2026-33380
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with…
Grafana
11.6.14 / 12.2.8+
MEDIUM 6.5
CVE-2026-28376
The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leadin…
Grafana
11.6.14 / 12.2.8+
MEDIUM 6.5
CVE-2026-28379
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fa…
Grafana
11.6.14 / 12.2.8+
HIGH 7.5
CVE-2026-21728
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment stra…
Tempo
2.8.4 / 2.9.2+
MEDIUM 5.3
CVE-2026-21726
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can …
Loki
3.6.4+
CRITICAL 9.1
CVE-2025-41118
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO…
Pyroscope
1.15.2+
MEDIUM 6.5
CVE-2025-12141
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.not…
Grafana
after 12.3.0
HIGH 7.5
CVE-2026-27877
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards.
No passwo…
Grafana
9.3.0 / 12.0.0+
HIGH 7.5
CVE-2026-27880
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.
Grafana
12.1.0 / 12.2.0+
MEDIUM 6.5
CVE-2026-27879
A resample query can be used to trigger out-of-memory crashes in Grafana.
Grafana
8.0.0 / 12.0.0+
MEDIUM 6.5
CVE-2026-28375
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
Grafana
8.1.0 / 12.0.0+
CRITICAL 9.1
CVE-2026-27876
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a…
Grafana
11.6.0 / 12.0.0+
HIGH 7.5
CVE-2026-28377
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthori…
Tempo
2.10.3+
MEDIUM 6.5
CVE-2026-33375
The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catast…
Grafana
11.6.14 / 12.1.10+
MEDIUM 5.3
CVE-2026-21722
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one c…
Grafana
11.6.10 / 12.1.6+