Vulnerability index

Browse CVEs

108 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-8609 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually e… Grafana 11.6.15 / 12.2.9+ Fix from $1,9502026-07-10 MEDIUM 5.4 CVE-2026-8595 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the bro… Grafana 12.4.4 / 13.0.2+ Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-33382 Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send ver… Grafana 11.6.15 / 12.2.9+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memor… Grafana after 13.0.1 Fix from $1,9502026-06-22 MEDIUM 5.4 CVE-2026-9029 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The … Grafana Mitigation only Fix from $1,6002026-06-22 HIGH 7.7 CVE-2026-42129 A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive back… Loki Datasource Mitigation only Fix from $1,9502026-06-22 HIGH 8.1 CVE-2026-28381 The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files… Snowflake after 1.14.12 Fix from $1,9502026-06-22 MEDIUM 6.5 CVE-2026-27878 A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting … Tempo 2.8.4 / 2.9.2+ Fix from $1,6002026-06-19 HIGH 8.8 CVE-2026-11769 We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation… Grafana Operator 5.24.0+ Fix from $1,9502026-06-13 HIGH 8.1 CVE-2026-33381 When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The … Grafana 11.6.14 / 12.2.8+ Fix from $1,9502026-05-13 HIGH 7.4 CVE-2026-33376 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to m… Grafana 11.6.14 / 12.2.8+ Fix from $1,9502026-05-13 HIGH 7.1 CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard t… Grafana 11.6.14 / 12.2.8+ Fix from $1,9502026-05-13 MEDIUM 6.5 CVE-2026-28380 Any Editor could delete any snapshot, even if they have no access to read or write them. Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-28383 A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authentic… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-33378 Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-resta… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-33380 A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-28376 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leadin… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 MEDIUM 6.5 CVE-2026-28379 A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fa… Grafana 11.6.14 / 12.2.8+ Fix from $1,6002026-05-13 HIGH 7.5 CVE-2026-21728 Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment stra… Tempo 2.8.4 / 2.9.2+ Fix from $1,9502026-04-24 MEDIUM 5.3 CVE-2026-21726 The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by double encoding, an attacker can … Loki 3.6.4+ Fix from $1,6002026-04-15 CRITICAL 9.1 CVE-2025-41118 Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (CO… Pyroscope 1.15.2+ Fix from $2,3002026-04-15 MEDIUM 6.5 CVE-2025-12141 In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.not… Grafana after 12.3.0 Fix from $1,6002026-04-15 HIGH 7.5 CVE-2026-27877 When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwo… Grafana 9.3.0 / 12.0.0+ Fix from $1,9502026-03-27 HIGH 7.5 CVE-2026-27880 The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. Grafana 12.1.0 / 12.2.0+ Fix from $1,9502026-03-27 MEDIUM 6.5 CVE-2026-27879 A resample query can be used to trigger out-of-memory crashes in Grafana. Grafana 8.0.0 / 12.0.0+ Fix from $1,6002026-03-27 MEDIUM 6.5 CVE-2026-28375 A testdata data-source can be used to trigger out-of-memory crashes in Grafana. Grafana 8.1.0 / 12.0.0+ Fix from $1,6002026-03-27 CRITICAL 9.1 CVE-2026-27876 A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a… Grafana 11.6.0 / 12.0.0+ Fix from $2,3002026-03-27 HIGH 7.5 CVE-2026-28377 A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthori… Tempo 2.10.3+ Fix from $1,9502026-03-26 MEDIUM 6.5 CVE-2026-33375 The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catast… Grafana 11.6.14 / 12.1.10+ Fix from $1,6002026-03-26 MEDIUM 5.3 CVE-2026-21722 Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one c… Grafana 11.6.10 / 12.1.6+ Fix from $1,6002026-02-12