Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Grafana

39 known vulnerabilities

3
CRITICAL
12
HIGH
21
MEDIUM
3
LOW

Top Products

grafana 31 tempo 3 loki datasource 1 snowflake 1 grafana operator 1 loki 1 pyroscope 1
39 CVEs
5.3
CVE-2026-8609

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory

6.8
CVE-2026-8595

A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that ex

7.5
CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing

3.1
CVE-2026-28378

The public dashboard deletion endpoint does not enforce organization isolation, allowing an Org Admin in one organizatio

7.5
CVE-2026-42127

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke

7.3
CVE-2026-9029

A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer

7.7
CVE-2026-42129

A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp

9.6
CVE-2026-28381

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da

5.4
CVE-2026-10601

A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni

6.5
CVE-2026-27878

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive

8.8
CVE-2026-11769

We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path t

5.9
CVE-2026-33381

When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few

6.3
CVE-2026-33380

A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi

6.5
CVE-2026-33378

Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s

7.1
CVE-2026-33377

An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr

7.4
CVE-2026-33376

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl

6.5
CVE-2026-28383

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b

6.5
CVE-2026-28380

Any Editor could delete any snapshot, even if they have no access to read or write them.

6.5
CVE-2026-28379

A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur

6.5
CVE-2026-28376

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req

4.3
CVE-2026-28374

Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t

7.5
CVE-2026-21728

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, dep

3.3
CVE-2026-21727

A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records.

5.3
CVE-2026-21726

The CVE-2021-36156 fix validates the namespace parameter for path traversal sequences after a single URL decode, by doub

9.1
CVE-2025-41118

Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten

6.5
CVE-2025-12141

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notif

6.5
CVE-2026-28375

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

7.5
CVE-2026-27880

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory cra

6.5
CVE-2026-27879

A resample query can be used to trigger out-of-memory crashes in Grafana.

6.5
CVE-2026-27877

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being u

9.1
CVE-2026-27876

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impac

7.5
CVE-2026-28377

A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, p

6.5
CVE-2026-33375

The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API rest

5.4
CVE-2026-21724

A vulnerability has been discovered in Grafana OSS where an authorization bypass in the provisioning contact points API

2.6
CVE-2026-21725

A time-of-create-to-time-of-use (TOCTOU) vulnerability lets recently deleted-then-recreated data sources be re-deleted w

5.3
CVE-2026-21722

Public dashboards with annotations enabled did not limit their annotation timerange to the locked timerange of the publi

6.8
CVE-2025-41117

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the b

8.1
CVE-2026-21721

The dashboard permissions API does not verify the target dashboard scope and only checks the dashboards.permissions:* ac

7.5
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10

Frequently Asked Questions

How many CVEs affect Grafana?

Grafana has 39 CVE records in our database, including 3 critical and 12 high severity vulnerabilities.

What are the most severe Grafana vulnerabilities?

Grafana has 3 critical severity (CVSS 9.0+) and 12 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Grafana vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Grafana products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Grafana Vulnerabilities

CyberStrike scans your infrastructure for Grafana vulnerabilities and provides real-time remediation guidance.

Get Started