← Back

CVE-2025-41117

nvd nist
Published: Feb 12, 2026Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

Affected (4)

Products: Grafana: Grafana
1 product
Grafana
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Grafana
From 12.2.0 to 12.2.4
From 12.3.0 to 12.3.2
Version 12.2.4
Version 12.3.2

References (1)

Timeline

No history available yet.