VYPR

Vendor CVEs

Grafana

All CVEs

154 total · sorted by risk
  • CVE-2026-72585MedAug 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An authorization bypass vulnerability in Grafana through 13.2.0 allows an Editor-role user to delete protected contact points (receivers) without the required alert.notifications.receivers.protected:write permission.

  • CVE-2026-27878MedJun 19, 2026
    risk 0.42cvss 6.5epss 0.00

    A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service.

  • CVE-2026-33378MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.

  • CVE-2026-28383MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

  • CVE-2026-28380MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    Any Editor could delete any snapshot, even if they have no access to read or write them.

  • CVE-2026-28379MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server.

  • CVE-2026-28376MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

  • CVE-2026-21728HigApr 24, 2026
    risk 0.42cvss 7.5epss 0.01

    Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively,…

  • CVE-2026-27880HigMar 27, 2026
    risk 0.42cvss 7.5epss 0.01

    The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

  • CVE-2026-28377HigMar 26, 2026
    risk 0.42cvss 7.5epss 0.00

    A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this…

  • CVE-2026-21720HigJan 27, 2026
    risk 0.42cvss 7.5epss 0.01

    Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an…

  • CVE-2024-1313MedMar 26, 2024
    risk 0.42cvss 6.5epss 0.01

    It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing a DELETE request to /api/snapshots/ using its view key. This functionality is intended to only be available to individuals with the…

  • CVE-2022-39306MedNov 9, 2022
    risk 0.42cvss 6.4epss 0.01

    Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the…

  • CVE-2021-28147MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.02

    The team sync HTTP API in Grafana Enterprise 6.x before 6.7.6, 7.x before 7.3.10, and 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service and having the EditorsCanAdmin feature enabled, this vulnerability allows…

  • CVE-2021-28146MedMar 22, 2021
    risk 0.42cvss 6.5epss 0.01

    The team sync HTTP API in Grafana Enterprise 7.4.x before 7.4.5 has an Incorrect Access Control issue. On Grafana instances using an external authentication service, this vulnerability allows any authenticated user to add external groups to existing teams. This can be used to…

  • CVE-2019-13068MedJun 30, 2019
    risk 0.42cvss 5.4epss 0.52

    public/app/features/panel/panel_ctrl.ts in Grafana before 6.2.5 allows HTML Injection in panel drilldown links (via the Title or url field).

  • CVE-2024-8996HigSep 25, 2024
    risk 0.40cvss 7.3epss 0.00

    Unquoted Search Path or Element vulnerability in Grafana Agent (Flow mode) on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Agent Flow: before 0.43.2

  • CVE-2024-8975HigSep 25, 2024
    risk 0.40cvss 7.3epss 0.00

    Unquoted Search Path or Element vulnerability in Grafana Alloy on Windows allows Privilege Escalation from Local User to SYSTEM This issue affects Alloy: before 1.3.3, from 1.4.0-rc.0 through 1.4.0-rc.1.

  • CVE-2022-46156HigNov 30, 2022
    risk 0.40cvss 7.2epss 0.00

    The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent prior to version 0.12.0 in their local network are impacted. The…

  • CVE-2020-12052MedApr 27, 2020
    risk 0.40cvss 6.1epss 0.01

    Grafana version < 6.7.3 is vulnerable for annotation popup XSS.

  • CVE-2024-1442MedMar 7, 2024
    risk 0.39cvss 6.0epss 0.01

    A user with the permissions to create a data source can use Grafana API to create a data source with UID set to *. Doing this will grant the user access to read, query, edit and delete all data sources within the organization.

  • CVE-2025-41117MedFeb 12, 2026
    risk 0.37cvss 6.8epss 0.00

    Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected;…

  • CVE-2022-39324MedJan 27, 2023
    risk 0.37cvss 6.7epss 0.01

    Grafana is an open-source platform for monitoring and observability. Prior to versions 8.5.16 and 9.2.8, malicious user can create a snapshot and arbitrarily choose the `originalUrl` parameter by editing the query, thanks to a web proxy. When another user opens the URL of the…

  • CVE-2022-44643MedDec 20, 2022
    risk 0.37cvss 5.7epss 0.00

    A vulnerability in the label-based access control of Grafana Labs Grafana Enterprise Metrics allows an attacker more access than intended. If an access policy which has label selector restrictions also has been granted access to all tenants in the system, the label selector…

  • CVE-2022-39201MedOct 13, 2022
    risk 0.37cvss 6.8epss 0.01

    Grafana is an open source observability and data visualization platform. Starting with version 5.0.0-beta1 and prior to versions 8.5.14 and 9.1.8, Grafana could leak the authentication cookie of users to plugins. The vulnerability impacts data source and plugin proxy endpoints…

  • CVE-2025-3580MedMay 23, 2025
    risk 0.36cvss 5.5epss 0.00

    An access control vulnerability was discovered in Grafana OSS where an Organization administrator could permanently delete the Server administrator account. This vulnerability exists in the DELETE /api/org/users/ endpoint. The vulnerability can be exploited when: 1. An…

  • CVE-2023-4457MedOct 16, 2023
    risk 0.36cvss 5.5epss 0.00

    Grafana is an open-source platform for monitoring and observability. The Google Sheets data source plugin for Grafana, versions 0.9.0 to 1.2.2 are vulnerable to an information disclosure vulnerability. The plugin did not properly sanitize error messages, making it potentially…

  • CVE-2021-31231MedApr 30, 2021
    risk 0.36cvss 5.5epss 0.00

    The Alertmanager in Grafana Enterprise Metrics before 1.2.1 and Metrics Enterprise 1.2.1 has a local file disclosure vulnerability when experimental.alertmanager.enable-api is used. The HTTP basic auth password_file can be used as an attack vector to send any file content via a…

  • CVE-2019-19499MedAug 28, 2020
    risk 0.36cvss 6.5epss 0.04

    Grafana <= 6.4.3 has an Arbitrary File Read vulnerability, which could be exploited by an authenticated attacker that has privileges to modify the data source configurations.

  • CVE-2026-10601MedJun 22, 2026
    risk 0.35cvss 5.4epss 0.00

    A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative…

  • CVE-2026-11769MedJun 13, 2026
    risk 0.35cvss epss 0.00

    We have released version 5.24.0 of the Grafana Operator. This patch includes a CRITICAL severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels…

  • CVE-2025-12141MedApr 15, 2026
    risk 0.35cvss 6.5epss 0.00

    In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic…

  • CVE-2026-28375MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

  • CVE-2026-27879MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    A resample query can be used to trigger out-of-memory crashes in Grafana.

  • CVE-2026-27877MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as…

  • CVE-2026-33375MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.00

    The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container.

  • CVE-2023-6152MedFeb 13, 2024
    risk 0.35cvss 5.4epss 0.01

    A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.

  • CVE-2023-22462MedMar 2, 2023
    risk 0.35cvss 6.4epss 0.02

    Grafana is an open-source platform for monitoring and observability. On 2023-01-01 during an internal audit of Grafana, a member of the security team found a stored XSS vulnerability affecting the core plugin "Text". The stored XSS vulnerability requires several user…

  • CVE-2022-21702MedFeb 8, 2022
    risk 0.35cvss 6.5epss 0.02

    Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting…

  • CVE-2021-41090MedDec 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in plaintext over two endpoints: metrics…

  • CVE-2020-13429MedMay 24, 2020
    risk 0.35cvss 5.4epss 0.01

    legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option.

  • CVE-2026-21723MedJul 23, 2026
    risk 0.34cvss 5.3epss 0.00

    The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is…

  • CVE-2026-33380MedMay 13, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable.

  • CVE-2026-21722MedFeb 12, 2026
    risk 0.34cvss 5.3epss 0.00

    Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the public dashboard. This means one could read the entire history of annotations visible on the specific dashboard, even those outside the locked timerange. This did…

  • CVE-2024-9476MedNov 13, 2024
    risk 0.33cvss epss 0.00

    A vulnerability in Grafana Labs Grafana OSS and Enterprise allows Privilege Escalation allows users to gain access to resources from other organizations within the same Grafana instance via the Grafana Cloud Migration Assistant.This vulnerability will only affect users who…

  • CVE-2024-8118MedSep 26, 2024
    risk 0.33cvss epss 0.01

    In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.

  • CVE-2023-5122MedFeb 14, 2024
    risk 0.33cvss 5.0epss 0.01

    Grafana is an open-source platform for monitoring and observability. The CSV datasource plugin is a Grafana Labs maintained plugin for Grafana that allows for retrieving and processing CSV data from a remote endpoint configured by an administrator. If this plugin was configured…

  • CVE-2023-1410MedMar 23, 2023
    risk 0.33cvss 6.2epss 0.01

    Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An…

  • CVE-2022-31123MedOct 13, 2022
    risk 0.33cvss 6.1epss 0.00

    Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though…

  • CVE-2018-18624MedJun 2, 2020
    risk 0.33cvss 6.1epss 0.01

    Grafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.