Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33378

Опубликовано: 13 мая 2026
Источник: redhat
CVSS3: 6.5

Описание

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

A flaw was found in Grafana. A remote attacker with authenticated access to a SQL datasource can exploit a vulnerability in the $__timeGroup macro. By sending specially crafted queries, an attacker can cause an Out of Memory (OOM) error, leading to the Grafana server crashing and resulting in a Denial of Service (DoS). This can disrupt the availability of the Grafana instance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Hardened Imageshi/grafanaNot affected
Red Hat Hardened Imagesgrafana13-1-main-13.1.6-0.1.hum1FixedRHSA-2026:6876717.09.2026
Red Hat Hardened Imagesgrafana13-2-main-13.2.1-0.5.hum1FixedRHSA-2026:6877817.09.2026
Red Hat Hardened Imagesgrafana12-4-main-12.4.10-0.6.hum1FixedRHSA-2026:6882118.09.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2477269grafana: Grafana: Denial of Service due to Out of Memory via $__timeGroup macro

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
nvd
4 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
debian
4 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading th ...

CVSS3: 6.5
github
4 месяца назад

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость встроенного макроса $__timeGroup платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3