Skip to content
Grafana LabsCVE-2026-19475

Grafana OSS: denial of service

Medium6.5CVE-2026-19475 · Published Sep 2, 2026 · updated Sep 3, 2026

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana OSS
Product
>= 11.6.0, <= 11.6.16No fix yet
>= 12.0.0, <= 12.0.10No fix yet
>= 12.1.0, <= 12.1.10No fix yet
>= 12.2.0, <= 12.2.10No fix yet
Microsoft SQL Server Datasource
Product
>= 13.0.0, <= 13.0.1No fix yet
MySQL Datasource
Product
>= 13.0.0, <= 13.0.2No fix yet
PostgreSQL Datasource
Product
>= 13.0.0, <= 13.0.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana Enterprise: capture-replay
Medium6.8Sep 2
Grafana: authentication bypass
High7.1Sep 2
Grafana Labs Alloy: exposed files
High7.7Aug 27
Grafana Labs Clickhouse Datasource: cleartext transmission
Medium6.1Aug 27
Grafana: improper access control
Medium6.3Aug 26
Grafana OSS: cross-site scripting
Medium6.8Aug 24

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.