Grafana — свободная программная система визуализации данных, ориентированная на данные систем ИТ-мониторинга.
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 11.6.16 | 11.6.16 | ||
| 11.6.15 | 11.6.15 | ||
| 11.6.14 | 11.6.14+security-04 | ||
| 11.6.14 | 11.6.14+security-01 | ||
| 11.6.14 | 11.6.14 | ||
| 11.6.13 | 11.6.13 | ||
| 11.6.12 | 11.6.12 | ||
| 11.6.11 | 11.6.11 | ||
| 11.6.10 | 11.6.10+security-01 | ||
| 11.6.10 | 11.6.10 |
Показывать по
Количество 600
GHSA-9758-8g25-vw94
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
CVE-2026-14199
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
CVE-2026-14199
Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing).
ELSA-2026-54184
ELSA-2026-54184: grafana security update (IMPORTANT)
BDU:2026-12009
Уязвимость компонента Alertmanager Templates Test Endpoint платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю вызвать отказ в обслуживании
GHSA-hhhx-wxgr-pj4r
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
GHSA-j7jj-549c-j492
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
GHSA-xcrv-g5fh-9wx2
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
CVE-2026-8609
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
CVE-2026-8595
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-9758-8g25-vw94 Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing). | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
CVE-2026-14199 Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing). | CVSS3: 7.1 | 0% Низкий | 22 дня назад | |
CVE-2026-14199 Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concatenated the username and forwarded identity attributes without a delimiter, so distinct identities could collide on one key. An authenticated user who shapes their own attributes to collide with a higher-privileged user's, while that user's cache entry is live, is authenticated as that user, up to Administrator (authentication bypass by spoofing). | CVSS3: 7.1 | 0% Низкий | 23 дня назад | |
ELSA-2026-54184 ELSA-2026-54184: grafana security update (IMPORTANT) | 0% Низкий | около 1 месяца назад | ||
BDU:2026-12009 Уязвимость компонента Alertmanager Templates Test Endpoint платформы для мониторинга и наблюдения Grafana, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
GHSA-hhhx-wxgr-pj4r A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting). | CVSS3: 6.8 | 0% Низкий | 3 месяца назад | |
GHSA-j7jj-549c-j492 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-xcrv-g5fh-9wx2 Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-8609 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
CVE-2026-8595 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting). | CVSS3: 6.8 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу