CVE-2026-33376
Vulnerability Summary
Timeline
Description
When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.
CVSS Metrics
- v3.1•HIGH•Score: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Trends
Current EPSS score: 0.28%• Percentile: 21%
Techniques & Countermeasures
- CWE-1188•Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure.
Affected Systems
- chainguard•grafana-12.0
all
- chainguard•grafana-12.1
all
- chainguard•grafana-12.4
< 12.4.3.02-r0
- chainguard•grafana-fips-12.0
all
- chainguard•grafana-fips-12.1
all
- chainguard•grafana-fips-12.4
< 12.4.4-r0
- wolfi•grafana-12.4
< 12.4.3.02-r0
- grafana•grafana
≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1
- grafana•grafana oss
≥ 9.4.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01