Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-54184

Опубликовано: 14 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2026-54184: grafana security update (IMPORTANT)

[10.2.6-23.1]

  • fix CVE-2026-42127: cap request body size and validate public dashboard access
  • Resolves RHEL-219382

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

grafana

10.2.6-23.el9_8.1

grafana-selinux

10.2.6-23.el9_8.1

Oracle Linux x86_64

grafana

10.2.6-23.el9_8.1

grafana-selinux

10.2.6-23.el9_8.1

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
nvd
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
redos
2 месяца назад

Уязвимость grafana

CVSS3: 7.5
github
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании