Direct Vulnerabilities

Known vulnerabilities in the grafana package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Authentication

<12.4.5-150200.3.91.1
  • M
Out-of-bounds Read

<12.4.5-150200.3.91.1
  • M
Race Condition

<12.4.5-150200.3.91.1
  • M
CVE-2026-33378

<12.4.5-150200.3.91.1
  • M
Uncontrolled Memory Allocation

<12.4.5-150200.3.91.1
  • H
Cross-site Scripting (XSS)

<12.4.5-150200.3.91.1
  • H
CVE-2026-39821

<12.4.5-150200.3.91.1
  • H
Improper Restriction of Rendered UI Layers or Frames

<12.4.5-150200.3.91.1
  • M
CVE-2026-28380

<12.4.5-150200.3.91.1
  • M
CVE-2026-28374

<12.4.5-150200.3.91.1
  • L
Time-of-check Time-of-use (TOCTOU)

<12.4.5-150200.3.91.1
  • M
CVE-2026-28376

<12.4.5-150200.3.91.1
  • M
CVE-2025-12141

<12.4.5-150200.3.91.1
  • M
CVE-2026-28383

<12.4.5-150200.3.91.1
  • M
CVE-2026-33381

<12.4.5-150200.3.91.1
  • H
CVE-2026-33382

<12.4.5-150200.3.91.1
  • H
CVE-2026-33376

<12.4.5-150200.3.91.1
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<12.4.5-150200.3.91.1
  • H
Resource Exhaustion

<12.4.5-150200.3.91.1
  • H
Improper Restriction of Rendered UI Layers or Frames

<12.4.5-150200.3.91.1
  • H
CVE-2026-33380

<12.4.5-150200.3.91.1
  • H
Improper Restriction of Rendered UI Layers or Frames

<12.4.5-150200.3.91.1
  • M
CVE-2026-28375

<11.6.14+security01-150200.3.88.1
  • H
Improper Authorization

<11.6.14+security01-150200.3.88.1
  • H
Uncaught Exception

<11.6.14+security01-150200.3.88.1
  • M
CVE-2026-33375

<11.6.14+security01-150200.3.88.1
  • L
Improper Input Validation

<11.6.14+security01-150200.3.88.1
  • H
Integer Overflow or Wraparound

<11.6.14+security01-150200.3.88.1
  • L
Time-of-check Time-of-use (TOCTOU)

<11.6.14+security01-150200.3.88.1
  • M
Out-of-bounds Write

<11.6.14+security01-150200.3.88.1
  • H
CVE-2026-27877

<11.6.14+security01-150200.3.88.1
  • M
CVE-2026-21724

<11.6.14+security01-150200.3.88.1
  • C
CVE-2026-27876

<11.6.14+security01-150200.3.88.1
  • M
Improper Initialization

<11.6.14+security01-150200.3.88.1
  • M
CVE-2025-3415

<11.6.11-150200.3.83.1
  • M
Information Exposure

<11.6.11-150200.3.83.1
  • H
CVE-2026-21721

<11.6.11-150200.3.83.1
  • H
CVE-2026-21720

<11.6.11-150200.3.83.1
  • H
Allocation of Resources Without Limits or Throttling

<11.6.11-150200.3.83.1
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

<11.5.10-150200.3.80.1
  • H
Improper Authorization

<11.5.10-150200.3.80.1
  • H
CVE-2025-6023

<11.5.10-150200.3.80.1
  • M
CVE-2025-47911

<11.5.10-150200.3.80.1
  • M
CVE-2025-6197

<11.5.10-150200.3.80.1
  • M
Information Exposure

<11.5.10-150200.3.80.1
  • M
CVE-2025-3415

<11.5.10-150200.3.80.1
  • M
CVE-2025-22872

<11.5.5-150200.3.72.2
  • M
CVE-2025-2703

<11.5.5-150200.3.72.2
  • L
Improper Input Validation

<11.5.5-150200.3.72.2
  • M
CVE-2023-45288

<11.5.5-150200.3.72.2
  • M
CVE-2024-9476

<11.5.5-150200.3.72.2
  • M
CVE-2025-22870

<11.5.5-150200.3.72.2
  • M
CVE-2025-3454

<11.5.5-150200.3.72.2
  • C
Arbitrary Command Injection

<11.5.5-150200.3.72.2