Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
164 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.3) | 0.29% | — | Grafana | 22/6/2026 | 10/7/2026 | A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend. | |
| Analizada | Media (6.5) | 0.41% | — | Grafana Tempo | 19/6/2026 | 29/6/2026 | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to trigger a denial of service against the Tempo service. | |
| Modificada | Media (6.4) | 0.36% | — | Grafana Operator | 13/6/2026 | 23/7/2026 | We have released version 5.24.0 of the Grafana Operator. This patch includes a MEDIUM severity security fix for a path traversal/privilege escalation vulnerability in the Grafana Operator. ### Summary The Grafana Operator supports loading dashboards & library panels using the jsonnet data templating language. The… | |
| Analizada | Alta (8.1) | 0.30% | — | Grafana | 13/5/2026 | 17/6/2026 | When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this. | |
| Analizada | Media (6.5) | 0.32% | — | Grafana | 13/5/2026 | 17/6/2026 | A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesystem. Only instances with the sqlExpressions feature toggle enabled are vulnerable. | |
| Analizada | Media (6.5) | 0.42% | — | Grafana | 13/5/2026 | 17/6/2026 | Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server. | |
| Analizada | Alta (7.1) | 0.23% | — | Grafana | 13/5/2026 | 17/6/2026 | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. | |
| Analizada | Alta (7.4) | 0.34% | — | Grafana | 13/5/2026 | 17/6/2026 | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here. | |
| Analizada | Media (6.5) | 0.42% | — | Grafana | 13/5/2026 | 17/6/2026 | A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service. | |
| Analizada | Media (6.5) | 0.30% | — | Grafana | 13/5/2026 | 17/6/2026 | Any Editor could delete any snapshot, even if they have no access to read or write them. | |
| Analizada | Media (6.5) | 0.32% | — | Grafana | 13/5/2026 | 17/6/2026 | A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent requests that cause a fatal map access error. This results in complete service unavailability requiring restart of the Grafana server. | |
| Analizada | Media (6.5) | 0.42% | — | Grafana | 13/5/2026 | 17/6/2026 | The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue. | |
| Analizada | Media (4.3) | 0.25% | — | Grafana | 13/5/2026 | 17/6/2026 | Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read the annotations. | |
| Modificada | Alta (7.5) | 0.64% | — | Grafana Tempo | 24/4/2026 | 9/9/2026 | Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service. | |
| Modificada | Baja (3.3) | 0.20% | — | Grafana | 15/4/2026 | 19/8/2026 | A cross-tenant isolation vulnerability was found in Grafana’s Correlations feature affecting legacy correlation records. Due to a backward compatibility condition allowing org_id = 0 records to be returned across organizations, a user with datasource management privileges could read and permanently delete legacy… | |
| Analizada | Media (5.3) | 0.41% | — | Grafana Loki | 15/4/2026 | 17/6/2026 | Thanks to Prasanth Sundararajan for reporting this vulnerability. | |
| Modificada | Crítica (9.1) | 0.41% | — | Grafana Pyroscope | 15/4/2026 | 7/10/2026 | Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Tencent Cloud Object Storage (COS). If the database is configured to use Tencent COS as the storage backend, an attacker could extract the secret_key configuration value from the Pyroscope API. To… | |
| Analizada | Baja (1.3) | 0.26% | — | Grafana | 15/4/2026 | 7/10/2026 | In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contact points created by… | |
| Analizada | Media (6.5) | 0.42% | — | Grafana | 27/3/2026 | 17/6/2026 | A testdata data-source can be used to trigger out-of-memory crashes in Grafana. | |
| Modificada | Alta (7.5) | 0.63% | — | Grafana | 27/3/2026 | 15/7/2026 | The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes. | |
| Analizada | Media (6.5) | 0.42% | — | Grafana | 27/3/2026 | 17/6/2026 | A resample query can be used to trigger out-of-memory crashes in Grafana. | |
| Modificada | Alta (7.5) | 0.40% | — | Grafana | 27/3/2026 | 15/7/2026 | When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments'… | |
| Modificada | Crítica (9.1) | 1.4% | 💥 PoC | Grafana | 27/3/2026 | 15/7/2026 | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlExpressions feature… | |
| Analizada | Alta (7.5) | 0.16% | — | Grafana Tempo | 26/3/2026 | 17/6/2026 | A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potentially allowing unauthorized users to obtain the key used to encrypt trace data stored in S3. Thanks to william_goodfellow for reporting this vulnerability. | |
| Analizada | Media (6.5) | 0.48% | — | Grafana | 26/3/2026 | 17/6/2026 | The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restrictions and trigger a catastrophic Out-Of-Memory (OOM) memory exhaustion, crashing the host container. |