Grafana
Grafana
See the latest tracked release, confirm when it was published, and subscribe for update emails.
13.0.4
- Release date
- July 21, 2026
- Security status
- 8 high-severity CVEs tracked in the last 90 days. Current version not affected.
Source
GitHub API
Public release notes are linked for the latest stored release.
Release history
See the latest published releases stored for this product.
| Version | Published | Notes |
|---|---|---|
| 13.0.4 | 2026-07-21 | Release Notes |
| 13.0.3 | 2026-06-23 | Release Notes |
| 13.0.2 | 2026-06-09 | Release Notes |
| 13.0.1 | 2026-04-17 | Release Notes |
| 13.0.0 | 2026-04-14 | Release Notes |
Vulnerability tracking
versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.
Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.
| CVE | Severity | Published | Status | Summary |
|---|---|---|---|---|
| CVE-2026-15583 | HIGH (8.6) | 2026-07-15 | Current versionnot affected | A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana service-account token by supplying a crafted X-Grafana-URL request header. This also enables SSRF against arbitrary internal services, including cloud metadata endpoints. Affected versions
|
| CVE-2026-8609 | HIGH (7.5) | 2026-07-10 | Current versionnot affected | An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service). Affected versions
Show 3 more
|
| CVE-2026-33382 | HIGH (7.5) | 2026-07-10 | Current versionnot affected | Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service. Affected versions
Show 3 more
|
| CVE-2026-42127 | HIGH (7.5) | 2026-06-22 | Current versionnot affected | The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. Affected versions
Show 3 more
|
| CVE-2026-9029 | HIGH (7.3) | 2026-06-22 | Current versionnot affected | A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting). Affected versions
|
| CVE-2026-33381 | HIGH (8.1) | 2026-05-13 | Current versionnot affected | When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few seconds after the event. The user will eventually lose access to do this. Affected versions
Show 3 more
|
| CVE-2026-33377 | HIGH (7.1) | 2026-05-13 | Current versionnot affected | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have write access to the dashboard to escalate privilege. Affected versions
Show 2 more
|
| CVE-2026-33376 | HIGH (7.4) | 2026-05-13 | Current versionnot affected | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here. Affected versions
Show 2 more
|