Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19475

Опубликовано: 02 сент. 2026
Источник: redhat
CVSS3: 6.5

Описание

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

An authenticated user with permission to query a SQL datasource (Microsoft SQL Server, PostgreSQL, or MySQL) could bypass the fix for CVE-2026-33375 by injecting the $__timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing fails to reject. Evaluating the injected macro triggers unbounded memory consumption, crashing the Grafana server process and causing a denial of service. The request can be repeated once the instance restarts.

Меры по смягчению последствий

Upgrade to a fixed Grafana release: 12.4.10 or later (12.4.x), 13.0.8 or later (13.0.x), or 13.1.5 or later (13.1.x and newer, includes 13.2.0+). Versions prior to 11.6.0 predate the vulnerable code path and are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Fix deferred
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph/grafana-rhel10Fix deferred
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 9grafanaNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2521852grafana: Grafana: SQL Data Source Plugin: OOM DoS via $__timeGroup macro

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
22 дня назад

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

CVSS3: 6.5
redos
3 дня назад

Уязвимость grafana

CVSS3: 6.5
redos
3 дня назад

Уязвимость grafana

CVSS3: 6.5
github
22 дня назад

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

6.5 Medium

CVSS3