Grafana

Grafana

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 15.04.2026 18:57:25
  • Zuletzt bearbeitet 19.08.2026 19:17:14

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource...

  • EPSS 0.26%
  • Veröffentlicht 15.04.2026 14:59:41
  • Zuletzt bearbeitet 07.10.2026 09:10:00

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which i...

  • EPSS 0.38%
  • Veröffentlicht 27.03.2026 14:28:56
  • Zuletzt bearbeitet 31.03.2026 18:56:31

A resample query can be used to trigger out-of-memory crashes in Grafana.

  • EPSS 0.38%
  • Veröffentlicht 27.03.2026 14:26:19
  • Zuletzt bearbeitet 31.03.2026 18:15:45

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

Medienbericht
  • EPSS 1.93%
  • Veröffentlicht 27.03.2026 14:24:36
  • Zuletzt bearbeitet 15.07.2026 02:19:11

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vecto...

Medienbericht
  • EPSS 0.77%
  • Veröffentlicht 27.03.2026 14:12:20
  • Zuletzt bearbeitet 15.07.2026 02:19:11

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

  • EPSS 0.31%
  • Veröffentlicht 27.03.2026 14:02:11
  • Zuletzt bearbeitet 15.07.2026 02:19:11

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to prox...

  • EPSS 0.24%
  • Veröffentlicht 26.03.2026 20:06:18
  • Zuletzt bearbeitet 14.04.2026 01:00:10

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API allows users with Editor role to modify protected webhook URLs without the required alert.notifications.receivers.protected:write ...

  • EPSS 0.43%
  • Veröffentlicht 26.03.2026 20:05:52
  • Zuletzt bearbeitet 31.03.2026 19:01:30

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

  • EPSS 0.16%
  • Veröffentlicht 25.02.2026 12:35:43
  • Zuletzt bearbeitet 10.05.2026 14:16:47

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to ...