{"id":"CLEANSTART-2026-LC55153","summary":"Security fixes for CVE-2026-21728, CVE-2026-2303, CVE-2026-28377, CVE-2026-42151, CVE-2026-44903, CVE-2026-48096, CVE-2026-55170, CVE-2026-55689, ghsa-8396-jffm-qx4w, ghsa-cf98-j28v-49v6, ghsa-cp6g-7hqx-qxhp, ghsa-ffqx-q65f-36jf, ghsa-fw8g-cg8f-9j28, ghsa-hcxc-wf8j-23hv, ghsa-mpwr-8vm7-h73f, ghsa-p4r4-xvrq-gvmc, ghsa-w8rr-5gcm-pp58, ghsa-wg65-39gg-5wfj applied in versions: 12.2.10-r1, 13.1.0-r1","details":"Multiple security vulnerabilities affect the grafana package. These issues are resolved in later releases. See references for individual vulnerability details.","modified":"2026-09-18T12:16:50.420514678Z","published":"2026-07-21T08:24:07.888703Z","withdrawn":"2026-09-18T11:59:01.768079Z","upstream":["CVE-2026-21728","CVE-2026-2303","CVE-2026-28377","CVE-2026-42151","CVE-2026-44903","CVE-2026-48096","CVE-2026-55170","CVE-2026-55689","ghsa-8396-jffm-qx4w","ghsa-cf98-j28v-49v6","ghsa-cp6g-7hqx-qxhp","ghsa-ffqx-q65f-36jf","ghsa-fw8g-cg8f-9j28","ghsa-hcxc-wf8j-23hv","ghsa-mpwr-8vm7-h73f","ghsa-p4r4-xvrq-gvmc","ghsa-w8rr-5gcm-pp58","ghsa-wg65-39gg-5wfj"],"database_specific":{},"references":[{"type":"ADVISORY","url":"https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-LC55153.json"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-21728"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-2303"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-28377"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-42151"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-44903"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-48096"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-55170"},{"type":"WEB","url":"https://osv.dev/vulnerability/CVE-2026-55689"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-8396-jffm-qx4w"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-cf98-j28v-49v6"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-cp6g-7hqx-qxhp"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-ffqx-q65f-36jf"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-fw8g-cg8f-9j28"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-hcxc-wf8j-23hv"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-mpwr-8vm7-h73f"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-p4r4-xvrq-gvmc"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-w8rr-5gcm-pp58"},{"type":"WEB","url":"https://osv.dev/vulnerability/ghsa-wg65-39gg-5wfj"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21728"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2303"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28377"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42151"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44903"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48096"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55170"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55689"}],"affected":[{"package":{"name":"grafana","ecosystem":"CleanStart"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"13.1.0-r1"}]}],"database_specific":{"source":"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-LC55153.json"}}],"schema_version":"1.9.0"}