Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:20984-1

Опубликовано: 15 июн. 2026
Источник: suse-cvrf

Описание

Security update for grafana

This update for grafana fixes the following issues:

Changes in grafana:

  • Fix multiple issues when parsing HTML files (bsc#1267153): CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506

Список пакетов

openSUSE Leap 16.0
grafana-11.6.14+security04-bp160.2.1

Описание

Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.


Затронутые продукты
openSUSE Leap 16.0:grafana-11.6.14+security04-bp160.2.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:grafana-11.6.14+security04-bp160.2.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:grafana-11.6.14+security04-bp160.2.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:grafana-11.6.14+security04-bp160.2.1

Ссылки

Описание

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.


Затронутые продукты
openSUSE Leap 16.0:grafana-11.6.14+security04-bp160.2.1

Ссылки