Back

MEDIUM

SQL Data Source Plugin: OOM DoS via $__timeGroup macro

Published Sep 2, 2026

Description

An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.

Affected products

Remediation

Red Hat mitigation

Upgrade to a fixed Grafana release: 12.4.10 or later (12.4.x), 13.0.8 or later (13.0.x), or 13.1.5 or later (13.1.x and newer, includes 13.2.0+). Versions prior to 11.6.0 predate the vulnerable code path and are not affected.

References (6)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GRAFANA
Published Sep 2, 2026
Updated Sep 3, 2026
Reserved Aug 10, 2026

CISA Vulnrichment

Updated Sep 2, 2026

NVD

Status Awaiting Analysis
Modified Sep 3, 2026

Red Hat

Severity Moderate
Public date Sep 2, 2026
Bugzilla 2521852

ENISA EUVD

Assigner GRAFANA
Published Sep 2, 2026
Updated Sep 3, 2026

GitHub

No data