Количество 574
Количество 574
GHSA-4368-7mjc-5763
A resample query can be used to trigger out-of-memory crashes in Grafana.
GHSA-3w66-95m3-8jxg
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
GHSA-3r2p-7499-27q3
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
GHSA-3q27-7qjq-p9c5
Grafana public dashboards disclose all direct mode datasources
GHSA-3p62-42x7-gxg5
Grafana User enumeration via forget password
GHSA-3j9m-hcv9-rpj8
XSS vulnerability allowing arbitrary JavaScript execution
GHSA-3hv4-r2fm-h27f
Email Validation Bypass And Preventing Sign Up From Email's Owner
GHSA-3f33-44xm-29m7
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard.
GHSA-2x6g-h2hg-rq84
Grafana Email addresses and usernames can not be trusted
GHSA-29p4-5443-x453
Any Editor could delete any snapshot, even if they have no access to read or write them.
CVE-2026-9029
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
CVE-2026-9029
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
CVE-2026-9029
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
CVE-2026-9029
A user with Editor permissions can place a malicious script in the att ...
CVE-2026-8609
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
CVE-2026-8609
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
CVE-2026-8595
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
CVE-2026-8595
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting).
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4368-7mjc-5763 A resample query can be used to trigger out-of-memory crashes in Grafana. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-3w66-95m3-8jxg The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-3r2p-7499-27q3 When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here. | CVSS3: 7.4 | 0% Низкий | 3 месяца назад | |
GHSA-3q27-7qjq-p9c5 Grafana public dashboards disclose all direct mode datasources | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-3p62-42x7-gxg5 Grafana User enumeration via forget password | CVSS3: 6.7 | 1% Низкий | около 2 лет назад | |
GHSA-3j9m-hcv9-rpj8 XSS vulnerability allowing arbitrary JavaScript execution | CVSS3: 6.9 | 85% Высокий | больше 4 лет назад | |
GHSA-3hv4-r2fm-h27f Email Validation Bypass And Preventing Sign Up From Email's Owner | CVSS3: 5.4 | 1% Низкий | больше 2 лет назад | |
GHSA-3f33-44xm-29m7 Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did not leak any annotations that would not otherwise be visible on the public dashboard. | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-2x6g-h2hg-rq84 Grafana Email addresses and usernames can not be trusted | CVSS3: 6.4 | 1% Низкий | около 2 лет назад | |
GHSA-29p4-5443-x453 Any Editor could delete any snapshot, even if they have no access to read or write them. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-9029 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-9029 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-9029 A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-9029 A user with Editor permissions can place a malicious script in the att ... | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-8609 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). | CVSS3: 5.3 | 0% Низкий | 20 дней назад | |
CVE-2026-8609 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). | CVSS3: 5.3 | 0% Низкий | 20 дней назад | |
CVE-2026-8595 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting). | CVSS3: 5.7 | 0% Низкий | 20 дней назад | |
CVE-2026-8595 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who views the dashboard (stored cross-site scripting). | CVSS3: 6.8 | 0% Низкий | 20 дней назад | |
CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу