Описание
ELSA-2026-54184: grafana security update (IMPORTANT)
[10.2.6-23.1]
- fix CVE-2026-42127: cap request body size and validate public dashboard access
- Resolves RHEL-219382
Обновленные пакеты
Oracle Linux 9
Oracle Linux aarch64
grafana
10.2.6-23.el9_8.1
grafana-selinux
10.2.6-23.el9_8.1
Oracle Linux x86_64
grafana
10.2.6-23.el9_8.1
grafana-selinux
10.2.6-23.el9_8.1
Связанные CVE
Связанные уязвимости
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании