[CLSA-2026:1785563141] grafana: Fix of 10 CVEs
Type:
security
Severity:
Important
Release date:
2026-08-01 05:45:59 UTC
Description:
- CVE-2026-21722: clamp public dashboard annotation queries to the dashboard's locked time range when time selection is disabled - CVE-2026-10601: reject Loki resource paths that escape /loki/api/v1/ and require Tempo trace ids to be hexadecimal - CVE-2026-28380: resolve the snapshot's dashboard by uid so the delete permission check is not skipped - CVE-2024-10452: require a matching org (or server admin) to revoke an invite - CVE-2026-28379: take the read lock around the managed-stream map lookup to stop a fatal concurrent map read/write crash - CVE-2026-28376: bound the Live push request body at 500k - CVE-2026-28383: bound the plugin resource request body at 128 MiB - CVE-2026-28375: cap testdata scenario data points at 10000 - CVE-2026-27879: bound the mathexp.Resample upsample length
Updated packages:
  • grafana-10.2.6-15.el9_6.tuxcare.els15.x86_64.rpm
    sha:bbfa5fb49baaa259096bde4640cfb3c40772d94d25a48d3bb5acd67a93fd26ae
  • grafana-selinux-10.2.6-15.el9_6.tuxcare.els15.x86_64.rpm
    sha:5cd10eea6681ebaf74ca4ef6eaa45a95a5ee479d9d01e71d6d522238f331a45b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.