Grafana OSS是Grafana公司开源的一个可视化仪表盘。 Grafana OSS 11.6.0版本存在安全漏洞,该漏洞源于Tempo和Loki datasource plugins在构造后端HTTP请求时将用户输入插入URL路径而未进行清理,可能导致路径遍历攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | Grafana OSS | 11.6.0≤ 11.6.14 |
affected |
12.2.0≤ 12.2.8 |
affected | ||
12.3.0≤ 12.3.6 |
affected | ||
12.4.0≤ 12.4.3 |
affected | ||
13.0.0≤ 13.0.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | Grafana OSS | 11.6.0 ~ 11.6.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28381 | 9.6 CRITICAL | Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT |
| CVE-2026-42129 | 7.7 HIGH | Path traversal in the Loki data source plugin |
| CVE-2026-42127 | 7.5 HIGH | Pre-authentication denial of service in the public dashboard query endpoint |
| CVE-2026-9029 | 7.3 HIGH | Stored XSS in the Geomap panel tile-layer attribution |
No comments yet