CVE-2026-19475

Aliases:CGA-6q59-hvqg-6c7qCGA-fwvx-f2rg-fmh7CGA-gp5p-3h93-j3wpCGA-jw4f-7h8g-hpfrCGA-v4gf-59w4-5xh2CGA-4f37-33cr-45pjCGA-5qpc-pj3m-m32pCGA-hmf5-392w-c8m8CGA-w9f9-fjh8-xvcwCGA-22jf-454x-jcc8CGA-2jch-9c8p-4w9hCGA-3qp3-g6vx-xvm7CGA-3r7q-2w48-8fqjCGA-3wqm-qqv5-jgc7CGA-4rm4-f8w6-2pj9CGA-6p6h-q33g-3wc9CGA-7mcp-8jp6-9f95CGA-99qm-4q24-fm3rCGA-9xrw-ghm9-vj52CGA-c8rq-x25c-r2cvCGA-cgq5-cv5g-j5p3CGA-fphq-fhh4-h4xhCGA-gmc6-vvr9-xp3pCGA-hg84-9pvq-q77fCGA-hwr9-7264-pm85CGA-jwr5-4fh8-7qvfCGA-mmcr-x4j8-xvfpCGA-mp53-53wg-2jj4CGA-mr6p-4gqp-p7wgCGA-rxpw-xg6f-mfhcCGA-rxvp-j83x-w4rwCGA-vq4f-rjx6-5jc7CGA-vqhm-53cp-v965CGA-xc6c-fpj5-ppf3CGA-xggr-2gv2-hw9cCGA-x625-x5c8-5jfmCGA-2h4h-9jjx-4453CGA-5q49-4hmj-hjqxCGA-r9vw-6wxx-x2j6CGA-4588-7rjm-g99xCGA-8pv5-9h6r-923wCGA-95jv-566x-mwrjCGA-r752-rhw2-56p9CGA-v334-hj2g-fjqgCGA-456p-mvvr-r5c8CGA-62m4-j847-jq9rCGA-63fp-mggv-pwm4CGA-95jc-9rgr-mw3wCGA-974m-g68r-74prCGA-h37g-7vrc-rxv9CGA-h3r3-rr4v-877hCGA-h7wh-qh69-wr2vCGA-j3g4-338g-rch2CGA-m22w-fh5c-6hp9CGA-m449-7vw7-47hfCGA-m873-53j5-vg9vCGA-q2r6-mwmp-ggqqCGA-q726-63r6-r59fCGA-q7j4-rpxv-p6c2CGA-w26j-g2jq-4cf6CGA-x63c-wc5v-xc8hCGA-x7wf-8hxc-p5fj
Advisory lineage Upstream: 0 Downstream: 1
Awaiting Analysis
Published: 02 Sept 2026, 15:56
Last modified:03 Sept 2026, 08:08

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.4% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

02 Sept 2026, 15:56
Published
Vulnerability first disclosed
03 Sept 2026, 08:08
Last Modified
Vulnerability information updated

Description

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.40% Percentile: 34%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • chainguardgrafana-11.6

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.2

    all

  • chainguardgrafana-12.3

    all

  • chainguardgrafana-13.1

    all | < 13.1.5-r0

  • chainguardgrafana-fips-11.6

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.2

    all

  • chainguardgrafana-fips-12.3

    all

  • chainguardpercona-grafana

    all

  • wolfigrafana-12.3

    all

  • grafanagrafana oss

    ≥ 11.6.0, ≤ 11.6.16 | ≥ 12.0.0, ≤ 12.0.10 | ≥ 12.1.0, ≤ 12.1.10 | ≥ 12.2.0, ≤ 12.2.10 | ≥ 12.3.0, ≤ 12.3.11 | ≥ 12.4.0, ≤ 12.4.9 | ≥ 13.0.0, ≤ 13.0.7 | ≥ 13.1.0, ≤ 13.1.4

  • grafanamicrosoft sql server datasource

    ≥ 13.0.0, ≤ 13.0.1

  • grafanamysql datasource

    ≥ 13.0.0, ≤ 13.0.2

  • grafanapostgresql datasource

    ≥ 13.0.0, ≤ 13.0.1

References (1)