Grafana Labs Security
Grafana, Loki, Tempo, Pyroscope security advisories.
24 advisories tracked · showing 24
- Aug 27, 2026CVE-2026-19854Disclosed before NVD
clickhouse-datasource silently drops TLS over PDC
- Aug 26, 2026CVE-2026-19197Disclosed before NVD
Broken access control in dashboard snapshots
- Aug 24, 2026CVE-2026-17033Disclosed before NVD
Grafana OSS: Stored XSS via external Alertmanager generatorURL
- Aug 11, 2026CVE-2026-19516CVE-2026-15583
Grafana MCP server-side request forgery via X-Grafana-URL header (grafana_api_request)
- Jul 22, 2026CVE-2026-21723Disclosed before NVD
DoS Vulnerability in Templates Test endpoint
- Jul 15, 2026CVE-2026-21729Disclosed before NVD
Loki detected_fields query limits results in unbounded memory allocation
- Jul 15, 2026CVE-2026-15583Disclosed before NVD
Grafana MCP server-side request forgery via X-Grafana-URL header
- Jun 13, 2026CVE-2026-11769MediumDisclosed before NVD
Operator - Namespaced User Path Traversal
- Jun 9, 2026CVE-2026-9029Disclosed before NVD
Stored XSS in the Geomap panel tile-layer attribution
- Jun 9, 2026CVE-2026-42127Disclosed before NVD
Pre-authentication denial of service in the public dashboard query handler
- Jun 9, 2026CVE-2026-8609Disclosed before NVD
Pre-authentication denial of service in the OAuth login route
- Jun 9, 2026CVE-2026-10601Disclosed before NVD
Path traversal in the Tempo and Loki data source plugins
- Jun 9, 2026CVE-2026-42129Disclosed before NVD
Path traversal in the Loki data source leads to internal information disclosure
- Jun 9, 2026CVE-2026-33382Disclosed before NVD
Grafana denial of service via oversized request bodies (web.Bind)
- May 13, 2026CVE-2026-28379Disclosed before NVD
Viewer-triggered race condition in Grafana Live leads to complete server crash
- May 13, 2026CVE-2026-33381Disclosed before NVD
Users can generate Service Account tokens after permissions removal
- May 13, 2026CVE-2026-33380Disclosed before NVD
SQL Expressions Read File From Disk
- May 13, 2026CVE-2026-28374Disclosed before NVD
IDOR in Annotations API allows unprivileged users to DELETE annotation
- May 13, 2026CVE-2026-28383Disclosed before NVD
Grafana plugin resources can lead to unbounded memory allocation
- May 13, 2026CVE-2026-28376Disclosed before NVD
Grafana Live push endpoint allows unbounded memory allocation leading to OOM
- May 13, 2026CVE-2026-33378Disclosed before NVD
Grafana Data Source Plugin: DoS (OOM) via Negative Interval Injection in $__timeGroup Macro
- May 13, 2026CVE-2026-33377Disclosed before NVD
Dashboard Import Overwrites ACL — Editor Privilege Escalation to Dashboard Admin
- May 13, 2026CVE-2026-28380Disclosed before NVD
BAC in Snapshot API allows deletion of unauthorized dashboard snapshots
- May 13, 2026CVE-2026-33376Disclosed before NVD
Auth Proxy IPv6 whitelist bypass