Nixpkgs Security Tracker

Login with GitHub

Suggestions search

With package: python314Packages.grafanalib

Found 4 matching suggestions

View:
Compact
Detailed
Permalink CVE-2026-27880
7.5 HIGH
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 days, 6 hours ago
OpenFeature evaluation API reads input data with no bounds

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

Affected products

Grafana
  • <v12.1.10
  • <v12.3.6
  • <v12.4.2
  • <v12.2.8

Matching in nixpkgs

Permalink CVE-2026-28375
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 days, 6 hours ago
Grafana Testdata datasource can issue unbounded memory allocations

A testdata data-source can be used to trigger out-of-memory crashes in Grafana.

Affected products

Grafana
  • <v12.3.6
  • <v12.2.8
  • <v12.4.2
  • <v12.1.10
  • <v11.6.14

Matching in nixpkgs

Permalink CVE-2026-27879
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 days, 6 hours ago
Query resampling can cause unbounded memory allocations

A resample query can be used to trigger out-of-memory crashes in Grafana.

Affected products

Grafana
  • <v12.3.6
  • <v12.2.8
  • <v12.4.2
  • <v12.1.10
  • <v11.6.14

Matching in nixpkgs

Permalink CVE-2026-27877
6.5 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV):
  • Attack complexity (AC):
  • Privileges required (PR):
  • User interaction (UI):
  • Scope (S):
  • Confidentiality impact (C):
  • Integrity impact (I):
  • Availability impact (A):
created 2 days, 6 hours ago
Public dashboards discloses all direct mode datasources

When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as possible to improve your deployments' security.

Affected products

Grafana
  • <v12.3.6
  • <v12.2.8
  • <v12.4.2
  • <v12.1.10
  • <v11.6.14

Matching in nixpkgs