VYPR

apk package

chainguard/commercial-grafana-13.1

pkg:apk/chainguard/commercial-grafana-13.1

Vulnerabilities (4)

  • CVE-2026-55170lowJun 18, 2026
    affected < 13.1.1-r0fixed 13.1.1-r0

    ## Description In OpenFGA, when MySQL is being used as the datastore, two distinct check requests can return the same response. ## Preconditions This applies if the following preconditions are met: 1. You run OpenFGA with MySQL as the datastore 2. Your authorization decisions

  • CVE-2026-48096MedJun 10, 2026
    affected < 13.1.1-r0fixed 13.1.1-r0

    OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is enabled, two distinct check requests can produce the same cache key, leading to OpenFGA reusing an earlier cached result for a subsequent request. This issue has

  • CVE-2026-42154HigMay 4, 2026
    affected < 13.1.0-r0fixed 13.1.0-r0

    Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote read endpoint (/api/v1/read) does not validate the declared decoded length in a snappy-compressed request body before allocating memory. An unauthenticated atta

  • CVE-2026-42151HigMay 4, 2026
    affected < 13.1.0-r0fixed 13.1.0-r0

    Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/azuread) was typed as string instead of Secret. Prometheus redacts fields of type