Grafana
39 known vulnerabilities
Top Products
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory
A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing
The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke
A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer
A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp
The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da
A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive
We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t
When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few
A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi
Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s
An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl
A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b
Any Editor could delete any snapshot, even if they have no access to read or write them.
A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur
The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req
Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t
Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, dep
A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records.
The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub
Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif
A testdata data-source can be used to trigger out-of-memory crashes in Grafana.
The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra
A resample query can be used to trigger out-of-memory crashes in Grafana.
When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u
A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac
A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p
The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest
A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API
A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w
Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi
Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b
The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* ac
Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10
Frequently Asked Questions
How many CVEs affect Grafana?
Grafana has 39 CVE records in our database, including 3 critical and 12 high severity vulnerabilities.
What are the most severe Grafana vulnerabilities?
Grafana has 3 critical severity (CVSS 9.0+) and 12 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Grafana vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Grafana products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Grafana Vulnerabilities
CyberStrike scans your infrastructure for Grafana vulnerabilities and provides real-time remediation guidance.
Get Started