<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T07:43:39.227521+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:54243</id>
    <title>ALSA-2026:54243 — Important: grafana security update</title>
    <updated>2026-10-04T07:43:39.353886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: grafana, AlmaLinux:8: grafana-selinux</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377)
  * grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:54243"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-10801</id>
    <title>bdu:2026-10801</title>
    <updated>2026-10-04T07:43:39.353957+00:00</updated>
    <content>bdu:2026-10801</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-10801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-grafana-2026-42127</id>
    <title>BIT-grafana-2026-42127 — Pre-authentication denial of service in the public dashboard query endpoint</title>
    <updated>2026-10-04T07:43:39.353974+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: grafana</p>
<p>The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-grafana-2026-42127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-360212</id>
    <title>EUVD-2026-360212</title>
    <updated>2026-10-04T07:43:39.353996+00:00</updated>
    <content>EUVD-2026-360212</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-360212"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42127</id>
    <title>fkie_cve-2026-42127</title>
    <updated>2026-10-04T07:43:39.354008+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42127"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3w66-95m3-8jxg</id>
    <title>GHSA-3w66-95m3-8jxg — Grafana: Pre-authentication denial of service in the public dashboard query handler</title>
    <updated>2026-10-04T07:43:39.354030+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/grafana/grafana</p>
<p>The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3w66-95m3-8jxg"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11332-1</id>
    <title>openSUSE-SU-2026:11332-1 — grafana-12.4.5-3.1 on GA media</title>
    <updated>2026-10-04T07:43:39.354054+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana-12.4.5-3.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11332-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:47618</id>
    <title>RHSA-2026:47618 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
    <updated>2026-10-04T07:43:39.354073+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads hono: Hono - Timing Attack in basicAuth and bearerAuth Middleware</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:47618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:54184</id>
    <title>RLSA-2026:54184 — Important: grafana security update</title>
    <updated>2026-10-04T07:43:39.354089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:9: grafana</p>
<p>Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB &amp; OpenTSDB.</p>
<p>Security Fix(es):</p>
<p>* grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:54184"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42127</id>
    <title>UBUNTU-CVE-2026-42127</title>
    <updated>2026-10-04T07:43:39.354111+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:16.04:LTS: grafana</p>
<p>The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-42127"/>
  </entry>
</feed>
