Known Vulnerabilities for Grafana OSS by Grafana
Listed below are 10 of the newest known vulnerabilities associated with "Grafana OSS" by "Grafana".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33380 json | A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's filesys... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-33375 json | The Grafana MSSQL data source plugin contains a logic flaw that allows a low-privileged user (Viewer) to bypass API restricti... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-28383 json | A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body i... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-28379 json | A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concurrent ... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-28377 json | A vulnerability in Grafana Tempo exposes the S3 SSE-C encryption key in plaintext through the /status/config endpoint, potent... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-28376 json | The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request ... | Not Provided | 2026-05-13 | 2026-05-14 |
| CVE-2026-28375 json | A testdata data-source can be used to trigger out-of-memory crashes in Grafana. | Not Provided | 2026-03-27 | 2026-03-31 |
| CVE-2026-27879 json | A resample query can be used to trigger out-of-memory crashes in Grafana. | Not Provided | 2026-03-27 | 2026-03-31 |
| CVE-2026-27876 json | A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RC... | Not Provided | 2026-03-27 | 2026-04-02 |
| CVE-2026-21727 json | --- title: Cross-Tenant Legacy Correlation Disclosure and Deletion draft: false hero: image: /static/img/heros/hero-legal2.... | Not Provided | 2026-04-15 | 2026-04-20 |