拥有查询 SQL 数据源权限的认证用户,可以通过在 WHERE 子句中注入 宏来绕过针对 CVE-2026-33375 的修复措施。Grafana 基于正则表达式的宏解析器不会拒绝这种注入。当该被注入的宏被求值时,会引发不受控的内存消耗,从而导致 Grafana 服务器进程终止,造成服务不可用(DoS)。受影响的数据源包括 Microsoft SQL Server、PostgreSQL 和 MySQL。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Grafana | PostgreSQL Datasource | 13.0.0 ~ 13.0.1 | - |
|
| Grafana | MySQL Datasource | 13.0.0 ~ 13.0.2 | - |
|
| Grafana | Grafana OSS | 11.6.0 ~ 11.6.16 | - |
|
| Grafana | Microsoft SQL Server Datasource | 13.0.0 ~ 13.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14199 | 7.1 HIGH | CVE-2026-14199 CVE Record |
| CVE-2026-12704 | 6.8 MEDIUM | CVE-2026-12704 CVE Record |
No comments yet