Описание
Security update for grafana
This update for grafana fixes the following issues:
Changes in grafana:
- CVE-2026-33382: Limit the size of the request body before processing it at several Grafana API endpoints (bsc#1271331)
- CVE-2026-8595: Fix stored XSS in the table panel (bsc#1271557)
Список пакетов
openSUSE Leap 16.0
grafana-12.4.5-bp160.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1271327
- SUSE Bug 1271331
- SUSE Bug 1271557
- SUSE CVE CVE-2026-33382 page
- SUSE CVE CVE-2026-8595 page
Описание
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Затронутые продукты
openSUSE Leap 16.0:grafana-12.4.5-bp160.2.1
Ссылки
- CVE-2026-33382
- SUSE Bug 1271331
Описание
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
Затронутые продукты
openSUSE Leap 16.0:grafana-12.4.5-bp160.2.1
Ссылки
- CVE-2026-8595
- SUSE Bug 1271557