grafana-10.2.6-23.el9_8.1
エラータID: AXSA:2026-1633:24
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
* grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-42127
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
Update packages.
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
N/A
SRPMS
- grafana-10.2.6-23.el9_8.1.src.rpm
MD5: efd1cc542bd0237c26e11ad409e71769
SHA-256: bd18ac0fe20c8f669dff00a3505688693ef8cf09fee2102b90c531346e591e19
Size: 336.14 MB
Asianux Server 9 for x86_64
- grafana-10.2.6-23.el9_8.1.x86_64.rpm
MD5: 52d3508e20791446934de06c49458550
SHA-256: b3c4dedf01e8d0e769c3879deeaecb73d84e7ba25a1d6b9b9a0811ff5522e222
Size: 113.95 MB - grafana-selinux-10.2.6-23.el9_8.1.x86_64.rpm
MD5: dab22369c1d51e541b9fde2c75e0268f
SHA-256: 01afa55a6d57d74c720d0bdf33179836a98829942cb44f00ce2d30284fd63920
Size: 24.96 kB