Release date:
2026-08-01 05:45:59 UTC
Description:
- CVE-2026-21722: clamp public dashboard annotation queries to the dashboard's
locked time range when time selection is disabled
- CVE-2026-10601: reject Loki resource paths that escape /loki/api/v1/ and
require Tempo trace ids to be hexadecimal
- CVE-2026-28380: resolve the snapshot's dashboard by uid so the delete
permission check is not skipped
- CVE-2024-10452: require a matching org (or server admin) to revoke an invite
- CVE-2026-28379: take the read lock around the managed-stream map lookup to
stop a fatal concurrent map read/write crash
- CVE-2026-28376: bound the Live push request body at 500k
- CVE-2026-28383: bound the plugin resource request body at 128 MiB
- CVE-2026-28375: cap testdata scenario data points at 10000
- CVE-2026-27879: bound the mathexp.Resample upsample length
Updated packages:
-
grafana-10.2.6-15.el9_6.tuxcare.els15.x86_64.rpm
sha:bbfa5fb49baaa259096bde4640cfb3c40772d94d25a48d3bb5acd67a93fd26ae
-
grafana-selinux-10.2.6-15.el9_6.tuxcare.els15.x86_64.rpm
sha:5cd10eea6681ebaf74ca4ef6eaa45a95a5ee479d9d01e71d6d522238f331a45b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.