{"id":"CGA-c3r7-rcc9-m2xp","modified":"2026-09-24T18:26:13.381271699Z","published":"2026-09-22T12:53:01Z","upstream":["CVE-2026-42129","GHSA-f74p-cwhp-x2wx"],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42129"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/3fcdbc5a6e5c955bd42bd3715dd03cbad2b078c1"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/42cdc39124912a8506a0c613c319c345aa950b29"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/82ef13993059351bf21de35b8488bbd9b42df4f4"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/d27d2eba9c509d16f214d290436a6ad0bd9c6c01"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/dd5dc51681ff0133ddb2e206c2ea318713aeca16"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/eeb08ceb020c4381242d8400e5878044e9877505"},{"type":"WEB","url":"https://github.com/grafana/grafana/commit/f70d3e480274a5dbd12006338c393f4b05d441ca"},{"type":"PACKAGE","url":"https://github.com/grafana/grafana"},{"type":"WEB","url":"https://github.com/grafana/grafana/releases/tag/v11.6.15"},{"type":"WEB","url":"https://github.com/grafana/grafana/releases/tag/v12.2.9"},{"type":"WEB","url":"https://github.com/grafana/grafana/releases/tag/v12.3.7"},{"type":"WEB","url":"https://github.com/grafana/grafana/releases/tag/v12.4.4"},{"type":"WEB","url":"https://github.com/grafana/grafana/releases/tag/v13.0.2"},{"type":"WEB","url":"https://grafana.com/security/security-advisories/cve-2026-42129"}],"affected":[{"package":{"name":"grafana-fips-12.1","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/grafana-fips-12.1?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"ecosystem_specific":{"components":[{"component_location":"/usr/bin/grafana-cli","component_purl":"pkg:golang/github.com/grafana/grafana@v12.1.11","latest_event_status":"fix_not_planned","latest_event_timestamp":"2026-09-23T14:03:49Z","component_name":"github.com/grafana/grafana","component_version":"v12.1.11","component_type":"go-module"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-c3r7-rcc9-m2xp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}