SQL Data Source Plugin: OOM DoS via $__timeGroup macro
Published Sep 2, 2026
6.5
MEDIUMCVSS 3.1
EPSS 0.40%
Description
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Affected products
-
Affected
- ≥ 11.6.0, ≤ 11.6.16
- ≥ 12.0.0, ≤ 12.0.10
- ≥ 12.1.0, ≤ 12.1.10
- ≥ 12.2.0, ≤ 12.2.10
- ≥ 12.3.0, ≤ 12.3.11
- ≥ 12.4.0, ≤ 12.4.9
- ≥ 13.0.0, ≤ 13.0.7
- ≥ 13.1.0, ≤ 13.1.4
-
Affected
- ≥ 13.0.0, ≤ 13.0.1
-
Affected
- ≥ 13.0.0, ≤ 13.0.2
-
Affected
- ≥ 13.0.0, ≤ 13.0.1
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Grafana | Grafana OSS | unaffected | Affected
|
| Grafana | Microsoft SQL Server Datasource | unaffected | Affected
|
| Grafana | MySQL Datasource | unaffected | Affected
|
| Grafana | PostgreSQL Datasource | unaffected | Affected
|
No data.
No data.
Multicluster Global Hub
multicluster-globalhub/multicluster-globalhub-grafana-rhel9
Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/acm-grafana-rhel9
Fix deferred
Red Hat Ceph Storage 5
rhceph/rhceph-5-dashboard-rhel8
Fix deferred
Red Hat Ceph Storage 6
rhceph/rhceph-6-dashboard-rhel9
Fix deferred
Red Hat Ceph Storage 7
rhceph/grafana-rhel9
Fix deferred
Red Hat Ceph Storage 8
rhceph/grafana-rhel9
Fix deferred
Red Hat Ceph Storage 9
rhceph/grafana-rhel10
Fix deferred
Red Hat Enterprise Linux 10
grafana
Fix deferred
Red Hat Enterprise Linux 8
grafana
Not affected
Red Hat Enterprise Linux 9
grafana
Not affected
Red Hat Hardened Images
grafana12.4
Affected
Red Hat Hardened Images
grafana13.1
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Fix deferred | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Fix deferred | n/a |
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Fix deferred | n/a |
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Fix deferred | n/a |
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Fix deferred | n/a |
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Fix deferred | n/a |
| Red Hat Ceph Storage 9 | rhceph/grafana-rhel10 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | grafana | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | grafana | Not affected | n/a |
| Red Hat Enterprise Linux 9 | grafana | Not affected | n/a |
| Red Hat Hardened Images | grafana12.4 | Affected | n/a |
| Red Hat Hardened Images | grafana13.1 | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Upgrade to a fixed Grafana release: 12.4.10 or later (12.4.x), 13.0.8 or later (13.0.x), or 13.1.5 or later (13.1.x and newer, includes 13.2.0+). Versions prior to 11.6.0 predate the vulnerable code path and are not affected.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-19475 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2521852 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-70104 Advisory
- https://grafana.com/security/security-advisories/cve-2026-19475 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-19475
- https://www.cve.org/CVERecord?id=CVE-2026-19475
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data