{"id":"SUSE-SU-2026:4600-1","summary":"Security update for grafana, system-user-grafana","details":"This update for grafana, system-user-grafana fixes the following issues:\n\n- Update to version 12.4.10:\n  * Security:\n    CVE-2026-17183: Fix exposing data accessible through Grafana's\n                    configured datasource credentials (bsc#1275934)\n    CVE-2026-2303: Drop dependency on vulnerable\n                   go.mongodb.org/mongo-driver (bsc#1269841)\n    CVE-2026-17033: Fix stored XSS via external Alertmanager\n                    generatorURL (bsc#1276426)\n    CVE-2026-73501: Fix fail-open authentication bypass in\n                    github.com/getkin/kin-openapi (bsc#1276973)\n    CVE-2026-19475: Fix DoS in PostgreSQL Datasource (bsc#1278307)\n    CVE-2026-14199: Fix session takeover via Auth Proxy cache key\n                    collision (bsc#1278322)\n  * Bug fixes:\n    Dashboards: Fix adhoc and groupby variable datasource on UI\n                import\n    Dashboards: Fix version dates and user display names in the\n                legacy version history page\n- Update to version 12.4.9:\n  * Features and enhancements:\n    Dashboard Import: Labels in v2 schema\n  * Bug fixes:\n    Azure Monitor: fix migration for dimension filters\n- Update to version 12.4.8:\n  * Security:\n    CVE-2026-19197: Fix access control in dashboard snapshots\n                    (bsc#1277025)\n- Update to version 12.4.7:\n  * Security:\n    CVE-2026-56852: Fix infinite loop on truncated/invalid UTF-8\n                    input in golang.org/x/text/unicode/norm\n                    (bsc#1272008)\n  * Features and enhancements:\n    Dashboards: Get annotations and dashboard endpoint performance\n                improvements\n  * Bug fixes:\n    DashboardDS: Fix Mixed panels with a time override stuck in\n                 permanent loading\n- Update to version 12.4.6:\n  * Security:\n    CVE-2026-41178: Fix opentelemetry-go's baggage parsing\n                    (bsc#1276658)\n  * Features and enhancements:\n    Alerting: Add protected fields authorization check to\n              provisioning API\n    Alerting: Return 403 instead of 500 on contact point provenance\n              mismatch\n  * Bug fixes:\n    Jaeger: Handle gzip, deflate, and brotli compressed API\n            responses\n    Alerting: fix ORM table mapping bug causing SELECT alert_rule\n              columns FROM user on PostgreSQL\n- Drop 0005-Bump-edwards25519.patch\n\n    CVE-2026-39882: Prevent memory exhaustion DoS in OpenTelemetry\n                    OTLP HTTP exporters by updating to v1.43.0.\n                    (bsc#1274217)\n    CVE-2026-8595: Fix stored XSS in the table panel (bsc#1271557)\n    CVE-2026-42127: Fix DoS through memory exhaustion in grafana'a\n                    public dashboard query endpoint (bsc#1268868)\n    CVE-2026-9029: Fix arbitrary code execution and information\n                   disclosure via XSS in geomap panel (bsc#1272328)\n    CVE-2026-33814: Fix infinite loop in HTTP/2 transport by\n                    updating golang.org/x/net (bsc#1265763)\n    CVE-2026-8609: Fix pre-authentication DoS in the OAuth login\n                   route (bsc#1271330)\n  * CVE-2026-1229: Update github.com/cloudflare/circl to fix\n                   producing incorect output for specific inputs\n                   (bsc#1265525)\n                    (bsc#1262187)\n  * CVE-2026-21723: Fix DoS vulnerability in Templates Test\n                    endpoint (bsc#1272427)\n- CVE-2026-41606: Fix potential DoS in Apache Thrift (bsc#1263330)\n- Build only for SUSE distributions\n","modified":"2026-10-09T18:15:03.739543950Z","published":"2026-10-09T08:54:30Z","related":["CVE-2026-1229","CVE-2026-14199","CVE-2026-17033","CVE-2026-17183","CVE-2026-19197","CVE-2026-19475","CVE-2026-21723","CVE-2026-2303","CVE-2026-33814","CVE-2026-39882","CVE-2026-41178","CVE-2026-41606","CVE-2026-42127","CVE-2026-56852","CVE-2026-73501","CVE-2026-8595","CVE-2026-8609","CVE-2026-9029"],"upstream":["CVE-2026-1229","CVE-2026-14199","CVE-2026-17033","CVE-2026-17183","CVE-2026-19197","CVE-2026-19475","CVE-2026-21723","CVE-2026-2303","CVE-2026-33814","CVE-2026-39882","CVE-2026-41178","CVE-2026-41606","CVE-2026-42127","CVE-2026-56852","CVE-2026-73501","CVE-2026-8595","CVE-2026-8609","CVE-2026-9029"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264600-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262187"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263330"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265525"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265763"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268868"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269841"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271330"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271557"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272008"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272328"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272427"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274217"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275934"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276426"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276658"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276973"},{"type":"REPORT","url":"https://bugzilla.suse.com/1277025"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278307"},{"type":"REPORT","url":"https://bugzilla.suse.com/1278322"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-1229"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-14199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-17033"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-17183"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-19475"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21723"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-2303"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33814"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41178"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41606"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42127"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56852"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73501"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8595"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8609"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9029"}],"affected":[{"package":{"name":"grafana","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.4.10-150200.3.94.3"}]}],"ecosystem_specific":{"binaries":[{"grafana":"12.4.10-150200.3.94.3","system-user-grafana":"1.0.0-150200.5.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4600-1.json"}},{"package":{"name":"system-user-grafana","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/system-user-grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-150200.5.8.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"12.4.10-150200.3.94.3","system-user-grafana":"1.0.0-150200.5.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4600-1.json"}}],"schema_version":"1.9.0"}