CVE-2026-19475
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Grafana | PostgreSQL Datasource | 13.0.0 <= 13.0.1 | affected |
| Grafana | MySQL Datasource | 13.0.0 <= 13.0.2 | affected |
| Grafana | Grafana OSS | 11.6.0 <= 11.6.16 | affected |
| Grafana | Grafana OSS | 12.0.0 <= 12.0.10 | affected |
| Grafana | Grafana OSS | 12.1.0 <= 12.1.10 | affected |
| Grafana | Grafana OSS | 12.2.0 <= 12.2.10 | affected |
| Grafana | Grafana OSS | 12.3.0 <= 12.3.11 | affected |
| Grafana | Grafana OSS | 12.4.0 <= 12.4.9 | affected |
| Grafana | Grafana OSS | 13.0.0 <= 13.0.7 | affected |
| Grafana | Grafana OSS | 13.1.0 <= 13.1.4 | affected |
| Grafana | Microsoft SQL Server Datasource | 13.0.0 <= 13.0.1 | affected |
Weaknesses
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.