rpm package
almalinux/grafana
pkg:rpm/almalinux/grafana
Vulnerabilities (89)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56862 | Hig | 7.5 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | Aug 13, 2026 | Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef | |
| CVE-2026-56860 | Med | 5.9 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | Aug 13, 2026 | Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b | |
| CVE-2026-56859 | Hig | 7.5 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | Aug 13, 2026 | Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. | |
| CVE-2026-56858 | Med | 6.1 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | Aug 13, 2026 | Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS. | |
| CVE-2026-56853 | Hig | 7.5 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | Aug 13, 2026 | When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this. | |
| CVE-2026-33818 | Hig | 7.5 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | Aug 13, 2026 | Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. | |
| CVE-2026-8609 | Med | 5.3 | < 10.2.6-28.el10_2.4 | 10.2.6-28.el10_2.4 | Jul 10, 2026 | An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). | |
| CVE-2026-33382 | Hig | 7.5 | < 10.2.6-28.el10_2.4 | 10.2.6-28.el10_2.4 | Jul 10, 2026 | Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service. | |
| CVE-2026-42127 | Hig | 7.5 | < 9.2.10-32.el8_10.1 | 9.2.10-32.el8_10.1 | Jun 22, 2026 | The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid das | |
| CVE-2026-44740 | Med | 6.5 | < 9.2.10-32.el8_10 | 9.2.10-32.el8_10 | Jun 1, 2026 | Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise | |
| CVE-2026-39821 | Cri | 9.6 | < 10.2.6-27.el10_2 | 10.2.6-27.el10_2 | May 22, 2026 | The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program | |
| CVE-2026-33377 | Hig | 7.1 | < 10.2.6-28.el10_2.4 | 10.2.6-28.el10_2.4 | May 13, 2026 | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | |
| CVE-2026-33376 | Hig | 7.4 | < 10.2.6-28.el10_2.4 | 10.2.6-28.el10_2.4 | May 13, 2026 | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffe | |
| CVE-2026-42499 | Hig | 7.5 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | May 7, 2026 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. | |
| CVE-2026-39820 | Hig | 7.5 | < 10.2.6-23.el9_8.3 | 10.2.6-23.el9_8.3 | May 7, 2026 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations. | |
| CVE-2026-32283 | Hig | 7.5 | < 9.2.10-30.el8_10 | 9.2.10-30.el8_10 | Apr 8, 2026 | If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3. | |
| CVE-2026-32282 | Med | 6.4 | < 9.2.10-30.el8_10 | 9.2.10-30.el8_10 | Apr 8, 2026 | On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which R | |
| CVE-2026-32280 | Hig | 7.5 | < 9.2.10-30.el8_10 | 9.2.10-30.el8_10 | Apr 8, 2026 | During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls | |
| CVE-2026-27877 | Med | 6.5 | < 10.2.6-24.el10_1 | 10.2.6-24.el10_1 | Mar 27, 2026 | When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as pos | |
| CVE-2026-25679 | Hig | 7.5 | < 10.2.6-23.el10_1 | 10.2.6-23.el10_1 | Mar 6, 2026 | url.Parse insufficiently validated the host/authority component and accepted some invalid URLs. |
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
- affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
- affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
- affected < 9.2.10-32.el8_10.1fixed 9.2.10-32.el8_10.1
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid das
- affected < 9.2.10-32.el8_10fixed 9.2.10-32.el8_10
Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise
- affected < 10.2.6-27.el10_2fixed 10.2.6-27.el10_2
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program
- affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.
- affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffe
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
- affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
- affected < 9.2.10-30.el8_10fixed 9.2.10-30.el8_10
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.
- affected < 9.2.10-30.el8_10fixed 9.2.10-30.el8_10
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which R
- affected < 9.2.10-30.el8_10fixed 9.2.10-30.el8_10
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls
- affected < 10.2.6-24.el10_1fixed 10.2.6-24.el10_1
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as pos
- affected < 10.2.6-23.el10_1fixed 10.2.6-23.el10_1
url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.
Page 1 of 5