Grafana

Grafana

123 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 10.08.2026 10:41:30
  • Zuletzt bearbeitet 18.08.2026 14:18:07

Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

  • EPSS 0.33%
  • Veröffentlicht 23.07.2026 01:48:16
  • Zuletzt bearbeitet 23.07.2026 17:55:03

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint require...

  • EPSS 0.24%
  • Veröffentlicht 10.07.2026 14:59:35
  • Zuletzt bearbeitet 13.07.2026 20:51:42

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).

  • EPSS 0.4%
  • Veröffentlicht 10.07.2026 14:58:33
  • Zuletzt bearbeitet 13.07.2026 20:51:48

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

  • EPSS 0.39%
  • Veröffentlicht 10.07.2026 14:58:23
  • Zuletzt bearbeitet 13.07.2026 20:51:35

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a ...

  • EPSS 0.14%
  • Veröffentlicht 07.07.2026 21:08:04
  • Zuletzt bearbeitet 10.07.2026 16:05:56

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

  • EPSS 0.43%
  • Veröffentlicht 22.06.2026 16:31:28
  • Zuletzt bearbeitet 10.07.2026 16:16:30

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through m...

  • EPSS 0.25%
  • Veröffentlicht 22.06.2026 13:18:40
  • Zuletzt bearbeitet 10.07.2026 16:16:39

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site s...

  • EPSS 0.26%
  • Veröffentlicht 22.06.2026 13:18:31
  • Zuletzt bearbeitet 10.07.2026 16:16:22

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses...

  • EPSS 0.2%
  • Veröffentlicht 13.05.2026 19:28:40
  • Zuletzt bearbeitet 02.06.2026 19:29:02

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations.