VYPR

rpm package

almalinux/grafana

pkg:rpm/almalinux/grafana

Vulnerabilities (89)

  • CVE-2026-56862HigAug 13, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indef

  • CVE-2026-56860MedAug 13, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-b

  • CVE-2026-56859HigAug 13, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

  • CVE-2026-56858MedAug 13, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

  • CVE-2026-56853HigAug 13, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

  • CVE-2026-33818HigAug 13, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

  • CVE-2026-8609MedJul 10, 2026
    affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4

    An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

  • CVE-2026-33382HigJul 10, 2026
    affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4

    Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

  • CVE-2026-42127HigJun 22, 2026
    affected < 9.2.10-32.el8_10.1fixed 9.2.10-32.el8_10.1

    The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid das

  • CVE-2026-44740MedJun 1, 2026
    affected < 9.2.10-32.el8_10fixed 9.2.10-32.el8_10

    Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise

  • CVE-2026-39821CriMay 22, 2026
    affected < 10.2.6-27.el10_2fixed 10.2.6-27.el10_2

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-33377HigMay 13, 2026
    affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4

    An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege.

  • CVE-2026-33376HigMay 13, 2026
    affected < 10.2.6-28.el10_2.4fixed 10.2.6-28.el10_2.4

    When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffe

  • CVE-2026-42499HigMay 7, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.

  • CVE-2026-39820HigMay 7, 2026
    affected < 10.2.6-23.el9_8.3fixed 10.2.6-23.el9_8.3

    Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.

  • CVE-2026-32283HigApr 8, 2026
    affected < 9.2.10-30.el8_10fixed 9.2.10-30.el8_10

    If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

  • CVE-2026-32282MedApr 8, 2026
    affected < 9.2.10-30.el8_10fixed 9.2.10-30.el8_10

    On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which R

  • CVE-2026-32280HigApr 8, 2026
    affected < 9.2.10-30.el8_10fixed 9.2.10-30.el8_10

    During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls

  • CVE-2026-27877MedMar 27, 2026
    affected < 10.2.6-24.el10_1fixed 10.2.6-24.el10_1

    When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as pos

  • CVE-2026-25679HigMar 6, 2026
    affected < 10.2.6-23.el10_1fixed 10.2.6-23.el10_1

    url.Parse insufficiently validated the host/authority component and accepted some invalid URLs.

Page 1 of 5