Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19475— CVE-2026-19475 CVE Record

Quick assessment

Affected
Grafana PostgreSQL Datasource
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

拥有查询 SQL 数据源权限的认证用户,可以通过在 WHERE 子句中注入 宏来绕过针对 CVE-2026-33375 的修复措施。Grafana 基于正则表达式的宏解析器不会拒绝这种注入。当该被注入的宏被求值时,会引发不受控的内存消耗,从而导致 Grafana 服务器进程终止,造成服务不可用(DoS)。受影响的数据源包括 Microsoft SQL Server、PostgreSQL 和 MySQL。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1499 · Endpoint Denial of Service
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19475

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
CVE-2026-19475 CVE Record
Source: CVE Program / CVE List V5
Vulnerability Description
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Grafana PostgreSQL Datasource 13.0.0 ~ 13.0.1 -
Grafana MySQL Datasource 13.0.0 ~ 13.0.2 -
Grafana Grafana OSS 11.6.0 ~ 11.6.16 -
Grafana Microsoft SQL Server Datasource 13.0.0 ~ 13.0.1 -

II. Public POCs for CVE-2026-19475

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19475

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19475 (1)

Same Patch Batch · Grafana · 2026-09-02 · 3 CVEs total

CVE-2026-14199 7.1 HIGH CVE-2026-14199 CVE Record
CVE-2026-12704 6.8 MEDIUM CVE-2026-12704 CVE Record

IV. Related Vulnerabilities

V. Comments for CVE-2026-19475

No comments yet


Leave a comment