Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected. | |
| Title | CVE-2026-19475 CVE Record | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-09-02T15:56:33.568Z
Reserved: 2026-08-10T14:51:01.083Z
Link: CVE-2026-19475
No data.
Status : Received
Published: 2026-09-02T16:17:15.120
Modified: 2026-09-02T16:17:15.120
Link: CVE-2026-19475
No data.
OpenCVE Enrichment
No data.
No weakness.