PT-2026-84757 · Postgresql Global Development Group+3 · Postgresql+3

·

CVE-2026-19475

·

Published

2026-09-02

·

Updated

2026-09-08

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Grafana versions prior to 12.4.10-1.1
Description An authenticated user with permissions to query a SQL data source can cause a denial of service by injecting the timeGroup macro through a WHERE clause. Because the regex-based macro parsing does not reject this injection, evaluating the macro leads to uncontrolled memory consumption, which can terminate the server process. This issue affects Microsoft SQL Server, PostgreSQL, and MySQL data sources.
Recommendations Update to version 12.4.10-1.1.

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GRAFANA-2026-19475
CVE-2026-19475
OPENSUSE-SU-2026:11684-1

Affected Products

Grafana
Sql Server
Mysql Server
Postgresql