[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:20940-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T17:19:26.604Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":62,"duplicates":63,"related":64,"reserved_at":9,"published_at":89,"modified_at":90,"state":9,"summary":91,"references_raw":93,"kevs":289,"epss":9,"epss_history":290,"metrics":291,"affected":292},"OPENSUSE-SU-2026:20940-1","Security update for grafana\n\nThis update for grafana fixes the following issues:\n\nChanges in grafana:\n\n- CVE-2026-39821: Fix validation bypass and privilege escalation by\n  updating golang.org/x/net to version 0.55.0 (bsc#1266600)\n\n- Update to version 11.6.14+security-04:\n  Security:\n  * CVE-2026-28374: Fix insecure direct object reference in\n    Annotations API (bsc#1265290)\n  * CVE-2026-28376: Fix unbounded memory allocation in Grafana Live\n    push endpoint (bsc#1265289)\n  * CVE-2026-28383: Fix unbounded memory allocation in Grafana\n    plugin resources (bsc#1265286)\n  * CVE-2026-28380: Fix broken access control in Snapshot API\n    (bsc#1265287)\n  * CVE-2026-33376: Fix Auth Proxy IPv6 whitelist bypass\n    (bsc#1265285)\n  * CVE-2026-28379: Fix viewer-triggered race condition in\n    Grafana Live (bsc#1265288)\n  * CVE-2026-33377: Fix dashboard Editor Privilege Escalation\n    (bsc#1265284)\n  * CVE-2026-33378: Fix OOM exception in Grafana Data Source Plugin\n    (bsc#1265283)\n  * CVE-2026-33381: Prevent users from generating Service Account\n    tokens after permissions removal (bsc#1265281)\n  * CVE-2026-33380: Fix vulnerability in SQL Expressions allowing\n    an authenticated attacker to read arbitrary files from the\n    Grafana server’s filesystem (bsc#1265282)\n\n- CVE-2026-34986: Fix panic in JWE decryption (bsc#1262950)\n- CVE-2026-41602: Fix Integer Overflow or Wraparound vulnerability\n  in Apache Thrift (bsc#1263501)\n\n- CVE-2026-26958: Bump filippo.io/edwards25519 to version 1.1.1\n  (bsc#1258595)\n- CVE-2026-21725: Fix missing UID when deleting datasource by name\n  (bsc#1258873)\n\n- Update to version 11.6.14+security-01:\n  Security:\n  * CVE-2026-33375: Fix denial of Service via out-of-memory\n    exhaustion in MSSQL data source plugin (bsc#1260881)\n\n- Update to version 11.6.14:\n  Security:\n  * CVE-2026-27876: Fix remote arbitrary code execution via chained\n    SQL Expressions (bsc#1261025)\n  * CVE-2026-27877: Fix information disclosure of data-source\n    passwords via public dashboards (bsc#1261026)\n  * CVE-2026-28375: Fix denial of service via testdata data-source\n    (bsc#1261029)\n  * CVE-2026-27879: Fix denial of service via resample query\n    (bsc#1261027)\n  * CVE-2026-33186: Fix authorization bypass due to improper\n    validation of the HTTP/2 :path pseudo-header (bsc#1260263)\n  * CVE-2026-21724: Fix authorization bypass allows modification of\n    protected webhook URLs (bsc#1260878)\n\n- Update to version 11.6.13:\n  Enhancement:\n  * Wire the public dashboard service to the HTTP server\n\n- Update to version 11.6.12:\n  Enhancement:\n  * Update authentication redirect logic\n  Bug fix:\n  * Fix single panel render with variable references\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60],{"_key":15},"CVE-2025-29923",{"_key":17},"CVE-2025-30153",{"_key":19},"CVE-2026-21724",{"_key":21},"CVE-2026-21725",{"_key":23},"CVE-2026-26958",{"_key":25},"CVE-2026-27876",{"_key":27},"CVE-2026-27877",{"_key":29},"CVE-2026-27879",{"_key":31},"CVE-2026-28374",{"_key":33},"CVE-2026-28375",{"_key":35},"CVE-2026-28376",{"_key":37},"CVE-2026-28379",{"_key":39},"CVE-2026-28380",{"_key":41},"CVE-2026-28383",{"_key":43},"CVE-2026-33186",{"_key":45},"CVE-2026-33375",{"_key":47},"CVE-2026-33376",{"_key":49},"CVE-2026-33377",{"_key":51},"CVE-2026-33378",{"_key":53},"CVE-2026-33380",{"_key":55},"CVE-2026-33381",{"_key":57},"CVE-2026-34986",{"_key":59},"CVE-2026-39821",{"_key":61},"CVE-2026-41602",[],[],[65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},"2026-06-10T12:02:03Z","2026-06-13T18:24:19.477495413Z",{"cisa_kev":92,"cisa_ransomware":92,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[94,100,104,108,112,116,120,124,128,132,136,140,144,148,152,156,160,164,168,172,176,180,184,188,192,197,201,205,209,213,217,221,225,229,233,237,241,245,249,253,257,261,265,269,273,277,281,285],{"url":95,"sources":96,"tags":98},"https://bugzilla.suse.com/1258595",[97],"osv_opensuse",[99],"REPORT",{"url":101,"sources":102,"tags":103},"https://bugzilla.suse.com/1258873",[97],[99],{"url":105,"sources":106,"tags":107},"https://bugzilla.suse.com/1259999",[97],[99],{"url":109,"sources":110,"tags":111},"https://bugzilla.suse.com/1260263",[97],[99],{"url":113,"sources":114,"tags":115},"https://bugzilla.suse.com/1260878",[97],[99],{"url":117,"sources":118,"tags":119},"https://bugzilla.suse.com/1260881",[97],[99],{"url":121,"sources":122,"tags":123},"https://bugzilla.suse.com/1261025",[97],[99],{"url":125,"sources":126,"tags":127},"https://bugzilla.suse.com/1261026",[97],[99],{"url":129,"sources":130,"tags":131},"https://bugzilla.suse.com/1261027",[97],[99],{"url":133,"sources":134,"tags":135},"https://bugzilla.suse.com/1261029",[97],[99],{"url":137,"sources":138,"tags":139},"https://bugzilla.suse.com/1262950",[97],[99],{"url":141,"sources":142,"tags":143},"https://bugzilla.suse.com/1263501",[97],[99],{"url":145,"sources":146,"tags":147},"https://bugzilla.suse.com/1264764",[97],[99],{"url":149,"sources":150,"tags":151},"https://bugzilla.suse.com/1265281",[97],[99],{"url":153,"sources":154,"tags":155},"https://bugzilla.suse.com/1265282",[97],[99],{"url":157,"sources":158,"tags":159},"https://bugzilla.suse.com/1265283",[97],[99],{"url":161,"sources":162,"tags":163},"https://bugzilla.suse.com/1265284",[97],[99],{"url":165,"sources":166,"tags":167},"https://bugzilla.suse.com/1265285",[97],[99],{"url":169,"sources":170,"tags":171},"https://bugzilla.suse.com/1265286",[97],[99],{"url":173,"sources":174,"tags":175},"https://bugzilla.suse.com/1265287",[97],[99],{"url":177,"sources":178,"tags":179},"https://bugzilla.suse.com/1265288",[97],[99],{"url":181,"sources":182,"tags":183},"https://bugzilla.suse.com/1265289",[97],[99],{"url":185,"sources":186,"tags":187},"https://bugzilla.suse.com/1265290",[97],[99],{"url":189,"sources":190,"tags":191},"https://bugzilla.suse.com/1266600",[97],[99],{"url":193,"sources":194,"tags":195},"https://www.suse.com/security/cve/CVE-2025-29923",[97],[196],"WEB",{"url":198,"sources":199,"tags":200},"https://www.suse.com/security/cve/CVE-2025-30153",[97],[196],{"url":202,"sources":203,"tags":204},"https://www.suse.com/security/cve/CVE-2026-21724",[97],[196],{"url":206,"sources":207,"tags":208},"https://www.suse.com/security/cve/CVE-2026-21725",[97],[196],{"url":210,"sources":211,"tags":212},"https://www.suse.com/security/cve/CVE-2026-26958",[97],[196],{"url":214,"sources":215,"tags":216},"https://www.suse.com/security/cve/CVE-2026-27876",[97],[196],{"url":218,"sources":219,"tags":220},"https://www.suse.com/security/cve/CVE-2026-27877",[97],[196],{"url":222,"sources":223,"tags":224},"https://www.suse.com/security/cve/CVE-2026-27879",[97],[196],{"url":226,"sources":227,"tags":228},"https://www.suse.com/security/cve/CVE-2026-28374",[97],[196],{"url":230,"sources":231,"tags":232},"https://www.suse.com/security/cve/CVE-2026-28375",[97],[196],{"url":234,"sources":235,"tags":236},"https://www.suse.com/security/cve/CVE-2026-28376",[97],[196],{"url":238,"sources":239,"tags":240},"https://www.suse.com/security/cve/CVE-2026-28379",[97],[196],{"url":242,"sources":243,"tags":244},"https://www.suse.com/security/cve/CVE-2026-28380",[97],[196],{"url":246,"sources":247,"tags":248},"https://www.suse.com/security/cve/CVE-2026-28383",[97],[196],{"url":250,"sources":251,"tags":252},"https://www.suse.com/security/cve/CVE-2026-33186",[97],[196],{"url":254,"sources":255,"tags":256},"https://www.suse.com/security/cve/CVE-2026-33375",[97],[196],{"url":258,"sources":259,"tags":260},"https://www.suse.com/security/cve/CVE-2026-33376",[97],[196],{"url":262,"sources":263,"tags":264},"https://www.suse.com/security/cve/CVE-2026-33377",[97],[196],{"url":266,"sources":267,"tags":268},"https://www.suse.com/security/cve/CVE-2026-33378",[97],[196],{"url":270,"sources":271,"tags":272},"https://www.suse.com/security/cve/CVE-2026-33380",[97],[196],{"url":274,"sources":275,"tags":276},"https://www.suse.com/security/cve/CVE-2026-33381",[97],[196],{"url":278,"sources":279,"tags":280},"https://www.suse.com/security/cve/CVE-2026-34986",[97],[196],{"url":282,"sources":283,"tags":284},"https://www.suse.com/security/cve/CVE-2026-39821",[97],[196],{"url":286,"sources":287,"tags":288},"https://www.suse.com/security/cve/CVE-2026-41602",[97],[196],[],[],[],[293],{"ecosystem":294,"name":295,"vendor":296,"product":297,"cpe_part":9,"purl_type":298,"purl_namespace":296,"purl_name":297,"source":9,"versions":299},"openSUSE","grafana","opensuse","grafana&distro=openSUSE Leap 16.0","rpm",[300],{"version":301,"is_range":302,"range_type":303,"version_start":9,"version_start_type":9,"version_end":304,"version_end_type":305,"fixed_in":9},"lt11_6_14+security04_bp160_1_1",true,"ecosystem","11.6.14+security04-bp160.1.1","excluding"]