GHSA-crvv-6w6h-cv34

Suggest an improvement
Source
https://github.com/advisories/GHSA-crvv-6w6h-cv34
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/06/GHSA-crvv-6w6h-cv34/GHSA-crvv-6w6h-cv34.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-crvv-6w6h-cv34
Aliases
Published
2025-06-18T12:30:30Z
Modified
2025-06-20T06:28:28.180347Z
Downstream
Severity
  • 2.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
Grafana long dashboard title or panel name causes unresponsives
Details

In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

Database specific
{
    "nvd_published_at": "2025-06-18T10:15:31Z",
    "cwe_ids": [
        "CWE-20"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2025-06-18T18:20:27Z"
}
References

Affected packages

Go / github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
0.0.1-test
Fixed
11.6.2

Go / github.com/grafana/grafana

Package

Name
github.com/grafana/grafana
View open source insights on deps.dev
Purl
pkg:golang/github.com/grafana/grafana

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.0.0-20250521211231-e0ba4b480954