VYPR

Grafana

by Grafana

Source repositories

CVEs (130)

  • CVE-2026-8609MedJul 10, 2026
    risk 0.27cvss 5.3epss 0.00

    An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

  • CVE-2026-33382HigJul 10, 2026
    risk 0.27cvss 7.5epss 0.00

    Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

  • CVE-2023-2183MedJun 6, 2023
    risk 0.27cvss 4.1epss 0.01

    Grafana is an open-source platform for monitoring and observability. The option to send a test alert is not available from the user panel UI for users having the Viewer role. It is still possible for a user with the Viewer role to send a test alert using the API as the API…

  • CVE-2023-1387MedApr 26, 2023
    risk 0.27cvss 4.2epss 0.01

    Grafana is an open-source platform for monitoring and observability. Starting with the 9.1 branch, Grafana introduced the ability to search for a JWT in the URL query parameter auth_token and use it as the authentication token. By enabling the "url_login" configuration…

  • CVE-2025-3454MedJun 2, 2025
    risk 0.26cvss 5.0epss 0.00

    This vulnerability in Grafana's datasource proxy API allows authorization checks to be bypassed by adding an extra slash character in the URL path. Users with minimal permissions could gain unauthorized read access to GET endpoints in Alertmanager and Prometheus datasources. …

  • CVE-2022-31130MedOct 13, 2022
    risk 0.25cvss 4.9epss 0.01

    Grafana is an open source observability and data visualization platform. Versions of Grafana for endpoints prior to 9.1.8 and 8.5.14 could leak authentication tokens to some destination plugins under some conditions. The vulnerability impacts data source and plugin proxy…

  • CVE-2025-3415MedJul 17, 2025
    risk 0.21cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. The Grafana Alerting DingDing integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 10.4.19+security-01, 11.2.10+security-01, 11.3.7+security-01,…

  • CVE-2024-11741MedJan 31, 2025
    risk 0.21cvss 4.3epss 0.00

    Grafana is an open-source platform for monitoring and observability. The Grafana Alerting VictorOps integration was not properly protected and could be exposed to users with Viewer permission. Fixed in versions 11.5.0, 11.4.1, 11.3.3,  11.2.6, 11.1.11, 11.0.11 and 10.4.15

  • CVE-2022-39229MedOct 13, 2022
    risk 0.21cvss 4.3epss 0.01

    Grafana is an open source data visualization platform for metrics, logs, and traces. Versions prior to 9.1.8 and 8.5.14 allow one user to block another user's login attempt by registering someone else'e email address as a username. A Grafana user’s username and email address…

  • CVE-2021-43815MedDec 10, 2021
    risk 0.21cvss 4.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 has a directory traversal for arbitrary .csv files. It only affects instances that have the developer testing tool called TestData DB data source enabled and…

  • CVE-2026-28378LowJul 7, 2026
    risk 0.20cvss 3.1epss 0.00

    The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organization to delete public dashboards belonging to a different organization by supplying the target dashboard's identifiers.

  • CVE-2026-21725LowFeb 25, 2026
    risk 0.17cvss 2.6epss 0.00

    A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted without permission to do so. This requires several very stringent conditions to be met: - The attacker must have admin access to the specific datasource prior…

  • CVE-2026-21727LowApr 15, 2026
    risk 0.14cvss 3.3epss 0.00

    A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges…

  • CVE-2024-10452LowOct 29, 2024
    risk 0.14cvss 2.2epss 0.00

    Organization admins can delete pending invites created in an organization they are not part of.

  • CVE-2025-1088LowJun 18, 2025
    risk 0.11cvss 2.7epss 0.00

    In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

  • CVE-2021-27358HigMar 18, 2021
    risk 0.07cvss 7.5epss 0.83

    The snapshot feature in Grafana 6.7.3 through 7.4.1 can allow an unauthenticated remote attackers to trigger a Denial of Service via a remote API call if a commonly used configuration is set.

  • CVE-2021-43813MedDec 10, 2021
    risk 0.05cvss 4.3epss 0.57

    Grafana is an open-source platform for monitoring and observability. Grafana prior to versions 8.3.2 and 7.5.12 contains a directory traversal vulnerability for fully lowercase or fully uppercase .md files. The vulnerability is limited in scope, and only allows access to files…

  • CVE-2026-72585Aug 10, 2026
    risk 0.00cvss —epss 0.00

    Rejected reason: Red Hat CNA-LR concluded that this CVE is not valid.

  • CVE-2026-9765HigJul 24, 2026
    risk 0.00cvss 7.1epss 0.00

    Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can access resources they are not authorized to access. An attacker can bypass any access control mechanisms in a web application, and…

  • CVE-2026-15583HigJul 15, 2026
    risk 0.00cvss 8.6epss 0.01

    A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services,…

Page 6 of 7