Description:
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Security Fix(es):
* grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377)
* grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default (CVE-2026-33376)
Bug Fix(es) and Enhancement(s):
* Avoid unbounded memory growth [almalinux-9.8.z] (JIRA:AlmaLinux-242865)
* Limit the size of the request body before processing it (JIRA:AlmaLinux-242866)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
grafana-10.2.6-23.el9_8.2.aarch64.rpm |
ad32c4a117be7987c84ce38febc79d1b608362ab7e04e515c305e79ba771e8cd |
| aarch64 |
grafana-selinux-10.2.6-23.el9_8.2.aarch64.rpm |
d83282679f9529d71b520e0cc8770c3e3506c5a0e630f6235d39332be0aa408a |
| ppc64le |
grafana-10.2.6-23.el9_8.2.ppc64le.rpm |
d6c0df1f173140b42e865a767c29168eb3cd70a376d102a6964cbfa0558b1c67 |
| ppc64le |
grafana-selinux-10.2.6-23.el9_8.2.ppc64le.rpm |
e609fac96baee51989fe34033009792ebada8334a497825fa27b8c0d2b9dfd73 |
| s390x |
grafana-selinux-10.2.6-23.el9_8.2.s390x.rpm |
790f632b935d9dd6f3920d1574fdcf493b5ce742593ed2fd26c433043da8b1a4 |
| s390x |
grafana-10.2.6-23.el9_8.2.s390x.rpm |
960365124773afbf3eccb52fad2b210f72d800eb30191d26697ba0a93990c383 |
| x86_64 |
grafana-10.2.6-23.el9_8.2.x86_64.rpm |
a0ccf1ca2aee555e910eba32e4d5ebbf33bbb694f5291cb9453dfcd61986d947 |
| x86_64 |
grafana-selinux-10.2.6-23.el9_8.2.x86_64.rpm |
e2baf80ca498198bcbc00b1c476b1080b42043c44850ffdd76280146661d97ed |