Grafana Labs is a Leader in the 2026 Gartner® Magic Quadrant™ for Observability Platforms.
Learn more
Downloads
Contact Us
Grafana Cloud
Solutions
Pricing
Open Source
Learn
Docs
Company
AI/Search
Sign in
Sign up
Site Search
Ask AI
Security
/
Security Advisories
Security
Security Advisories
Showing 24 results, page 2 of 6
Published CVE records
Published
CVE
Severity (CVSS)
Product
Advisory Title
Updated
2026-06-09
CVE-2026-42127
High (7.5)
Grafana
Pre-authentication denial of service in the public dashboard query handler
—
2026-06-09
CVE-2026-9029
High (7.3)
Grafana
Stored XSS in the Geomap panel tile-layer attribution
—
2026-06-09
CVE-2026-8595
Medium (6.8)
Grafana
Stored XSS in the table panel (TableNG)
—
2026-05-13
CVE-2026-33376
High (7.4)
Grafana
Auth Proxy IPv6 whitelist bypass
—
2026-05-13
CVE-2026-28380
Medium (6.5)
Grafana
BAC in Snapshot API allows deletion of unauthorized dashboard snapshots
—
2026-05-13
CVE-2026-33377
High (7.1)
Grafana
Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
—
2026-05-13
CVE-2026-33378
Medium (6.5)
Grafana
Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
—
2026-05-13
CVE-2026-28376
Medium (6.5)
Grafana
Grafana Live push endpoint allows unbounded memory allocation leading to OOM
—
2026-05-13
CVE-2026-28383
Medium (6.5)
Grafana
Grafana plugin resources can lead to unbounded memory allocation
—
2026-05-13
CVE-2026-28374
Medium (4.3)
Grafana
IDOR in Annotations API allows unprivileged users to DELETE annotation
—
2026-05-13
CVE-2026-33380
Medium (6.3)
Grafana
SQL Expressions Read File From Disk
—
2026-05-13
CVE-2026-33381
Medium (5.9)
Grafana
Users can generate Service Account tokens after permissions removal
—
2026-05-13
CVE-2026-28379
Medium (6.5)
Grafana
Viewer-triggered race condition in Grafana Live leads to complete server crash
—
2026-05-02
CVE-2026-28381
Critical (9.6)
Grafana
Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT
—
2026-04-24
CVE-2026-21728
High (7.5)
Tempo
Tempo query limit results in unbounded memory allocation
—
2026-03-30
CVE-2026-28375
Medium (6.5)
Grafana
Grafana Testdata datasource can issue unbounded memory allocations
—
2026-03-30
CVE-2026-27880
High (7.5)
Grafana
OpenFeature evaluation API reads input data with no bounds
—
2026-03-30
CVE-2026-27877
Medium (6.5)
Grafana
Public dashboards discloses all direct mode datasources
—
2026-03-30
CVE-2026-27879
Medium (6.5)
Grafana
Query resampling can cause unbounded memory allocations
—
2026-03-30
CVE-2026-27876
Critical (9.1)
Grafana
RCE on Grafana via sqlExpressions
—
2026-03-25
CVE-2026-33375
Medium (6.5)
Grafana
Grafana MSSQL Data Source Plugin: Restriction Bypass Leading to OOM DoS
—
2026-03-25
CVE-2026-21724
Medium (5.4)
Grafana
Missing Protected-field Authorization in Provisioning Contact Points API
—
2026-03-24
CVE-2026-28378
Low (3.1)
Grafana
Cross-Organization Public Dashboard Deletion via Missing Org Isolation
—
2026-03-23
CVE-2026-27878
Medium (6.5)
Tempo
Tempo denial of service via TraceQL exemplars hint (TraceQL query execution)
—
Filter
Previous
1
2
3
4
5
6
Next
Security Advisories | Grafana Labs