grafana-fips-12.2

Direct Vulnerabilities

Known vulnerabilities in the grafana-fips-12.2 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-xcgv-8mv7-v8c7

<12.2.10-r1
  • L
GHSA-jpcw-4wr7-c3vq

<12.2.10-r1
  • L
CVE-2026-39822

<12.2.10-r1
  • L
CVE-2026-42505

<12.2.10-r1
  • L
GHSA-ff52-ph69-cf7x

<12.2.10-r1
  • L
GHSA-r277-6w6q-xmqw

<12.2.10-r1
  • L
Resource Exhaustion

<12.2.10-r0
  • L
GHSA-8rm2-7qqf-34qm

<12.2.10-r0
  • M
Cross-site Scripting (XSS)

<12.2.10-r0
  • L
GHSA-66c4-2g2v-54qw

<12.2.10-r0
  • L
GHSA-cqp7-wf4c-3xgc

<12.2.10-r0
  • H
CVE-2026-33381

<12.2.10-r0
  • L
Authorization Bypass Through User-Controlled Key

<12.2.10-r0
  • L
GHSA-wfhv-mj62-f5xh

<12.2.10-r0
  • L
GHSA-gxcp-jjxh-rwp4

<12.2.10-r0
  • M
CVE-2026-33380

<12.2.10-r0
  • L
GHSA-cp6g-7hqx-qxhp

<12.2.9-r2
  • L
CVE-2026-2303

<12.2.9-r2
  • L
GHSA-8396-jffm-qx4w

<12.2.9-r1
  • M
Insufficient Verification of Data Authenticity

<12.2.9-r1
  • L
CVE-2026-21726

<12.2.9-r0
  • L
GHSA-497x-rrr9-68jp

<12.2.9-r0
  • L
GHSA-w2q5-6q6x-x959

<12.2.8.04-r2
  • L
GHSA-4279-q6mj-392r

<12.2.8.04-r2
  • L
CVE-2026-42507

<12.2.8.04-r2
  • L
CVE-2026-27145

<12.2.8.04-r2
  • L
CVE-2026-42504

<12.2.8.04-r2
  • L
GHSA-h3gm-q7m7-mp28

<12.2.8.04-r2
  • L
GHSA-h524-452v-82p9

<12.2.8.04-r2
  • L
CVE-2026-39821

<12.2.8.04-r2
  • C
SQL Injection

<12.2.8.01-r4
  • L
GHSA-pjcq-xvwq-hhpj

<12.2.8.01-r4
  • L
Use of Incorrectly-Resolved Name or Reference

<12.2.8.01-r4
  • H
Integer Overflow or Wraparound

<12.2.8.01-r4
  • L
GHSA-57j5-qwp2-vqp6

<12.2.8.01-r4
  • L
GHSA-j88v-2chj-qfwx

<12.2.8.01-r4
  • L
GHSA-p9h5-jm8x-mjm5

<12.2.8.01-r3
  • L
Cross-site Scripting (XSS)

<12.2.8.01-r3
  • L
GHSA-h74g-238j-357m

<12.2.8.01-r3
  • L
GHSA-3v2c-x6q9-f697

<12.2.8.01-r3
  • L
GHSA-497x-jcxf-m478

<12.2.8.01-r3
  • M
Out-of-bounds Write

<12.2.8.01-r3
  • L
GHSA-2283-wf8c-rw8r

<12.2.8.01-r3
  • L
CVE-2026-39825

<12.2.8.01-r3
  • L
Improper Encoding or Escaping of Output

<12.2.8.01-r3
  • L
GHSA-5m4p-2gjx-p2g8

<12.2.8.01-r3
  • H
Double Free

<12.2.8.01-r3
  • L
CVE-2026-42499

<12.2.8.01-r3
  • M
Link Following

<12.2.8.01-r3
  • L
CVE-2026-42501

<12.2.8.01-r3
  • L
GHSA-xq5j-9r39-c3vf

<12.2.8.01-r3
  • L
GHSA-qc64-m6c2-v4x7

<12.2.8.01-r3
  • H
NULL Pointer Dereference

<12.2.8.01-r3
  • L
GHSA-8g2r-hhvj-mv99

<12.2.8.01-r3
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<12.2.8.01-r3
  • L
GHSA-qf3q-3h68-mmh2

<12.2.8.01-r3
  • H
Allocation of Resources Without Limits or Throttling

<12.2.8.01-r3
  • L
GHSA-wf45-q9ch-q8gh

<12.2.8.04-r1
  • L
Integer Overflow or Wraparound

<12.2.8.04-r1
  • L
CVE-2026-21728

<12.2.8.01-r3
  • L
GHSA-p4r4-xvrq-gvmc

<12.2.8.01-r3
  • L
GHSA-jwvj-g8pc-cx45

<12.2.8.01-r2
  • L
GHSA-68m9-983m-f3v5

<12.2.8.01-r2
  • L
Uncontrolled Memory Allocation

<12.2.8.01-r2
  • L
Information Exposure

<12.2.8.01-r2
  • H
Incorrect Authorization

<12.2.8.01-r2
  • L
GHSA-xmrv-pmrh-hhx2

<12.2.8.01-r2
  • L
GHSA-w8rr-5gcm-pp58

<12.2.8.01-r2
  • L
GHSA-q9hv-hpm4-hj6x

<12.2.8.01-r0
  • L
Out-of-bounds Write

<12.2.8.01-r0
  • L
GHSA-mp76-5xhh-vxvc

<12.2.8.01-r0
  • L
GHSA-3q27-7qjq-p9c5

<12.2.8.01-r0
  • L
GHSA-736h-475m-xhjc

<12.2.8.01-r0
  • L
CVE-2026-27876

<12.2.8.01-r0
  • C
CVE-2026-1229

<12.2.8.01-r0
  • L
GHSA-4368-7mjc-5763

<12.2.8.01-r0
  • L
CVE-2026-28375

<12.2.8.01-r0
  • L
CVE-2026-33375

<12.2.8.01-r0
  • M
CVE-2026-21724

<12.2.8.01-r0
  • L
GHSA-jmfj-8gxc-cg8c

<12.2.8.01-r0
  • H
CVE-2026-27877

<12.2.8.01-r0
  • L
Out-of-bounds Write

<12.2.8.01-r0
  • L
GHSA-9vq6-r4xh-vm55

<12.2.8.01-r0
  • L
GHSA-7g92-g4vh-hp84

<12.2.8.01-r0
  • H
Untrusted Search Path

<12.2.8.01-r1
  • L
GHSA-hfvc-g4fc-pqhx

<12.2.8.01-r1
  • L
GHSA-7mr4-xjxg-34g6

<12.2.7-r4
  • H
Improper Certificate Validation

<12.2.7-r4
  • L
GHSA-m4pr-4j3g-9v7v

<12.2.7-r4
  • M
Cross-site Scripting (XSS)

<12.2.7-r4
  • L
CVE-2026-32280

<12.2.7-r4
  • L
GHSA-5w89-2c2x-6x66

<12.2.7-r4
  • C
CVE-2026-27143

<12.2.7-r4
  • L
GHSA-cfp9-33rc-j74f

<12.2.7-r4
  • H
Allocation of Resources Without Limits or Throttling

<12.2.7-r4
  • H
Incorrect Authorization

<12.2.7-r4
  • L
GHSA-jrg3-gfjw-hm96

<12.2.7-r4
  • L
GHSA-cqrx-3m42-5p5w

<12.2.7-r4
  • L
GHSA-gjvh-7jh8-7xhm

<12.2.7-r4
  • L
GHSA-78h2-9frx-2jm8

<12.2.7-r4
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<12.2.7-r4
  • L
Uncaught Exception

<12.2.7-r4
  • L
Improper Validation of Array Index

<12.2.7-r2
  • C
Improper Input Validation

<12.2.7-r3
  • L
GHSA-h6c8-cww8-35hf

<12.2.7-r3
  • L
GHSA-6g7g-w4f8-9c9x

<12.2.7-r2
  • L
Improper Authorization

<12.2.7-r2
  • L
GHSA-p77j-4mvh-x3m3

<12.2.7-r2
  • L
GHSA-jq9f-gm9w-rwm9

<12.2.5-r0
  • H
Incorrect Authorization

<12.2.5-r0
  • L
GHSA-h355-32pf-p2xm

<12.2.4.01-r0
  • L
CVE-2025-61732

<12.2.4.01-r0
  • L
GHSA-8jvr-vh7g-f8gx

<12.2.4.01-r0
  • C
CVE-2025-68121

<12.2.4.01-r0
  • H
Improper Authorization

<12.2.4-r0
  • L
GHSA-2c64-vmv2-hgfc

<12.2.4-r0