- EPSS 0.03%
- Veröffentlicht 25.02.2026 12:35:43
- Zuletzt bearbeitet 27.02.2026 03:34:26
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to ...
CVE-2026-21722
- EPSS 0.01%
- Veröffentlicht 12.02.2026 09:16:08
- Zuletzt bearbeitet 27.02.2026 15:16:27
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the...
CVE-2025-41117
- EPSS 0.01%
- Veröffentlicht 12.02.2026 09:16:07
- Zuletzt bearbeitet 26.02.2026 22:20:42
Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP A...
CVE-2026-21720
- EPSS 0.02%
- Veröffentlicht 27.01.2026 09:15:48
- Zuletzt bearbeitet 17.02.2026 20:06:27
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks f...
CVE-2026-0712
- EPSS 0.05%
- Veröffentlicht 15.01.2026 13:16:04
- Zuletzt bearbeitet 22.01.2026 17:16:30
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22643
- EPSS 0.08%
- Veröffentlicht 15.01.2026 13:13:47
- Zuletzt bearbeitet 22.01.2026 18:16:45
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- EPSS 0.03%
- Veröffentlicht 15.01.2026 13:13:11
- Zuletzt bearbeitet 22.01.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22640
- EPSS 0.06%
- Veröffentlicht 15.01.2026 13:12:49
- Zuletzt bearbeitet 22.01.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22639
- EPSS 0.04%
- Veröffentlicht 15.01.2026 13:12:03
- Zuletzt bearbeitet 22.01.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-22638
- EPSS 0.04%
- Veröffentlicht 15.01.2026 13:11:21
- Zuletzt bearbeitet 22.01.2026 17:16:36
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.