SUSE-SU-2026:4600-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264600-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4600-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:4600-1
Upstream
CVE (18)
Related
Published
2026-10-09T08:54:30Z
Modified
2026-10-09T18:15:03Z
Summary
Security update for grafana, system-user-grafana
Details

This update for grafana, system-user-grafana fixes the following issues:

  • Update to version 12.4.10:

    • Security: CVE-2026-17183: Fix exposing data accessible through Grafana's configured datasource credentials (bsc#1275934) CVE-2026-2303: Drop dependency on vulnerable go.mongodb.org/mongo-driver (bsc#1269841) CVE-2026-17033: Fix stored XSS via external Alertmanager generatorURL (bsc#1276426) CVE-2026-73501: Fix fail-open authentication bypass in github.com/getkin/kin-openapi (bsc#1276973) CVE-2026-19475: Fix DoS in PostgreSQL Datasource (bsc#1278307) CVE-2026-14199: Fix session takeover via Auth Proxy cache key collision (bsc#1278322)
    • Bug fixes: Dashboards: Fix adhoc and groupby variable datasource on UI import Dashboards: Fix version dates and user display names in the legacy version history page
  • Update to version 12.4.9:

    • Features and enhancements: Dashboard Import: Labels in v2 schema
    • Bug fixes: Azure Monitor: fix migration for dimension filters
  • Update to version 12.4.8:

    • Security: CVE-2026-19197: Fix access control in dashboard snapshots (bsc#1277025)
  • Update to version 12.4.7:

    • Security: CVE-2026-56852: Fix infinite loop on truncated/invalid UTF-8 input in golang.org/x/text/unicode/norm (bsc#1272008)
    • Features and enhancements: Dashboards: Get annotations and dashboard endpoint performance improvements
    • Bug fixes: DashboardDS: Fix Mixed panels with a time override stuck in permanent loading
  • Update to version 12.4.6:

    • Security: CVE-2026-41178: Fix opentelemetry-go's baggage parsing (bsc#1276658)
    • Features and enhancements: Alerting: Add protected fields authorization check to provisioning API Alerting: Return 403 instead of 500 on contact point provenance mismatch
    • Bug fixes: Jaeger: Handle gzip, deflate, and brotli compressed API responses Alerting: fix ORM table mapping bug causing SELECT alert_rule columns FROM user on PostgreSQL
  • Drop 0005-Bump-edwards25519.patch

    CVE-2026-39882: Prevent memory exhaustion DoS in OpenTelemetry OTLP HTTP exporters by updating to v1.43.0. (bsc#1274217) CVE-2026-8595: Fix stored XSS in the table panel (bsc#1271557) CVE-2026-42127: Fix DoS through memory exhaustion in grafana'a public dashboard query endpoint (bsc#1268868) CVE-2026-9029: Fix arbitrary code execution and information disclosure via XSS in geomap panel (bsc#1272328) CVE-2026-33814: Fix infinite loop in HTTP/2 transport by updating golang.org/x/net (bsc#1265763) CVE-2026-8609: Fix pre-authentication DoS in the OAuth login route (bsc#1271330)

    • CVE-2026-1229: Update github.com/cloudflare/circl to fix producing incorect output for specific inputs (bsc#1265525) (bsc#1262187)
    • CVE-2026-21723: Fix DoS vulnerability in Templates Test endpoint (bsc#1272427)
  • CVE-2026-41606: Fix potential DoS in Apache Thrift (bsc#1263330)

  • Build only for SUSE distributions

References

Affected packages

SUSE:Linux Enterprise Module for Package Hub 15 SP7
grafana

Package

Name
grafana
Purl
pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
12.4.10-150200.3.94.3

Ecosystem specific

{
    "binaries": [
        {
            "grafana": "12.4.10-150200.3.94.3",
            "system-user-grafana": "1.0.0-150200.5.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4600-1.json"
system-user-grafana

Package

Name
system-user-grafana
Purl
pkg:rpm/suse/system-user-grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.0-150200.5.8.1

Ecosystem specific

{
    "binaries": [
        {
            "grafana": "12.4.10-150200.3.94.3",
            "system-user-grafana": "1.0.0-150200.5.8.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4600-1.json"