Количество 22
Количество 22
ELSA-2026-54243
ELSA-2026-54243: grafana security update (IMPORTANT)
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
CVE-2026-33377
An Editor can overwrite a dashboard not owned by them to acquire admin ...
ROS-20260714-80-0067
Уязвимость grafana
GHSA-3w66-95m3-8jxg
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
ELSA-2026-54184
ELSA-2026-54184: grafana security update (IMPORTANT)
BDU:2026-10801
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
GHSA-5cv7-h7gr-wjgh
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
BDU:2026-07034
Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перезаписью списков контроля доступа, позволяющая нарушителю повысить свои привилегии
ROS-20260714-73-0062
Уязвимость grafana
ROS-20260708-80-0036
Уязвимость grafana
ROS-20260708-73-0030
Уязвимость grafana
RLSA-2026:58982
Moderate: grafana security, bug fix, and enhancement update
ELSA-2026-58982
ELSA-2026-58982: grafana security, bug fix, and enhancement update (MODERATE)
RLSA-2026:54178
Moderate: grafana security, bug fix, and enhancement update
ELSA-2026-54178
ELSA-2026-54178: grafana security, bug fix, and enhancement update (MODERATE)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
ELSA-2026-54243 ELSA-2026-54243: grafana security update (IMPORTANT) | около 1 месяца назад | |||
CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-42127 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
CVE-2026-33377 An Editor can overwrite a dashboard not owned by them to acquire admin ... | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
ROS-20260714-80-0067 Уязвимость grafana | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-3w66-95m3-8jxg The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
ELSA-2026-54184 ELSA-2026-54184: grafana security update (IMPORTANT) | 0% Низкий | около 1 месяца назад | ||
BDU:2026-10801 Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-5cv7-h7gr-wjgh An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
BDU:2026-07034 Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с перезаписью списков контроля доступа, позволяющая нарушителю повысить свои привилегии | CVSS3: 7.1 | 0% Низкий | 4 месяца назад | |
ROS-20260714-73-0062 Уязвимость grafana | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
ROS-20260708-80-0036 Уязвимость grafana | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
ROS-20260708-73-0030 Уязвимость grafana | CVSS3: 7.1 | 0% Низкий | 2 месяца назад | |
RLSA-2026:58982 Moderate: grafana security, bug fix, and enhancement update | 20 дней назад | |||
ELSA-2026-58982 ELSA-2026-58982: grafana security, bug fix, and enhancement update (MODERATE) | 22 дня назад | |||
RLSA-2026:54178 Moderate: grafana security, bug fix, and enhancement update | около 1 месяца назад | |||
ELSA-2026-54178 ELSA-2026-54178: grafana security, bug fix, and enhancement update (MODERATE) | около 1 месяца назад |
Уязвимостей на страницу