Postgresql Global Development Group · Postgresql · CVE-2026-19475
**Name of the Vulnerable Software and Affected Versions**
Grafana versions prior to 12.4.10-1.1
**Description**
An authenticated user with permissions to query a SQL data source can cause a denial of service by injecting the `timeGroup` macro through a WHERE clause. Because the regex-based macro parsing does not reject this injection, evaluating the macro leads to uncontrolled memory consumption, which can terminate the server process. This issue affects Microsoft SQL Server, PostgreSQL, and MySQL data sources.
**Recommendations**
Update to version 12.4.10-1.1.