<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T15:12:35.568478+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2024-02627</id>
    <title>bdu:2024-02627</title>
    <updated>2026-10-05T15:12:35.576505+00:00</updated>
    <content>bdu:2024-02627</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2024-02627"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2022-39328</id>
    <title>BIT-grafana-2022-39328 — Grafana vulnerable to race condition allowing privilege escalation</title>
    <updated>2026-10-05T15:12:35.576543+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2022-39328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1006</id>
    <title>certfr-2022-avi-1006 — De multiples vulnérabilités ont été découvertes dans Grafana. Elles
permettent à un attaquant de provoquer une atteinte…</title>
    <updated>2026-10-05T15:12:35.576578+00:00</updated>
    <content>certfr-2022-avi-1006</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2022-avi-1006"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2022-78211</id>
    <title>cnvd-2022-78211</title>
    <updated>2026-10-05T15:12:35.576597+00:00</updated>
    <content>cnvd-2022-78211</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2022-78211"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-266775</id>
    <title>EUVD-2026-266775</title>
    <updated>2026-10-05T15:12:35.576610+00:00</updated>
    <content>EUVD-2026-266775</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-266775"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39328</id>
    <title>fkie_cve-2022-39328</title>
    <updated>2026-10-05T15:12:35.576620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-39328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vqc4-mpj8-jxch</id>
    <title>GHSA-vqc4-mpj8-jxch — Grafana Race condition allowing privilege escalation</title>
    <updated>2026-10-05T15:12:35.576641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>Today we are releasing Grafana 9.2.4. Alongside other bug fixes, this patch release includes critical security fixes for CVE-2022-39328.</p>
<p>Release 9.2.4, latest patch, also containing security fix:</p>
<p>- [Download Grafana 9.2.4](https://grafana.com/grafana/download/9.2.4)</p>
<p>Appropriate patches have been applied to [Grafana Cloud](https://grafana.com/cloud) and as always, we closely coordinated with all cloud providers licensed to offer Grafana Pro. They have received early notification under embargo and confirmed that their offerings are secure at the time of this announcement. This is applicable to Amazon Managed Grafana and Azure Managed Grafana as a service offering.</p>
<p>## Privilege escalation</p>
<p>### Summary</p>
<p>Internal security audit identified a race condition in the Grafana codebase, which allowed an unauthenticated user to query an arbitrary endpoint in Grafana.
A race condition in the [HTTP context creation](https://github.com/grafana/grafana/blob/main/pkg/web/router.go#L153) could make a HTTP request being assigned the authentication/authorization middlewares of another call. Under heavy load it is possible that a call protected by a privileged middleware receives instead the middleware of a public query. 
As a result, an unauthenticated user can successfully query protected endpoints.</p>
<p>The CVSS score for this vulnerability is [9.8 Critical](https://nvd.nist.gov/vuln-metrics/cvss/v3-calculator?vector=AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;version=3.1)</p>
<p>### Impact</p>
<p>Unauthenticated…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vqc4-mpj8-jxch"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-39328</id>
    <title>gsd-2022-39328</title>
    <updated>2026-10-05T15:12:35.576686+00:00</updated>
    <content>gsd-2022-39328</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-39328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39328</id>
    <title>UBUNTU-CVE-2022-39328</title>
    <updated>2026-10-05T15:12:35.576699+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>Grafana is an open-source platform for monitoring and observability. Versions starting with 9.2.0 and less than 9.2.4 contain a race condition in the authentication middlewares logic which may allow an unauthenticated user to query an administration endpoint under heavy load. This issue is patched in 9.2.4. There are no known workarounds.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39328"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0334</id>
    <title>WID-SEC-W-2023-0334 — Grafana: Mehrere Schwachstellen</title>
    <updated>2026-10-05T15:12:35.576716+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, authentisierter oder anonymer Angreifer kann mehrere Schwachstellen in Grafana ausnutzen, um Benutzerrechte zu erlangen, seine Privilegien zu erweitern und um Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0334"/>
  </entry>
</feed>
