Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:54184

Опубликовано: 16 сент. 2026
Источник: rocky
Оценка: Important

Описание

Important: grafana security update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
grafanaaarch6423.el9_8.1grafana-10.2.6-23.el9_8.1.aarch64.rpm
grafana-selinuxaarch6423.el9_8.1grafana-selinux-10.2.6-23.el9_8.1.aarch64.rpm
grafanax86_6423.el9_8.1grafana-10.2.6-23.el9_8.1.x86_64.rpm
grafana-selinuxx86_6423.el9_8.1grafana-selinux-10.2.6-23.el9_8.1.x86_64.rpm

Показывать по

Связанные CVE

Исправления

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
redhat
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
nvd
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
redos
2 месяца назад

Уязвимость grafana

CVSS3: 7.5
github
3 месяца назад

Grafana: Pre-authentication denial of service in the public dashboard query handler