{"id":"SUSE-SU-2026:3718-1","summary":"Security update for grafana","details":"This update for grafana fixes the following issues:\n\ngrafana updated from version 11.6.14+security04 to version 12.4.5:\n\nSecurity fixes:\n\n- CVE-2026-39882: Prevent memory exhaustion DoS in OpenTelemetry OTLP HTTP exporters (bsc#1274217)\n- CVE-2026-33382: Limit the size of the request body before processing it at several Grafana API endpoints (bsc#1271331)\n- CVE-2025-12141: Fixed information leakage in Grafana Alerting (bsc#1262187)\n- CVE-2026-41607: Fix potential information disclosure in Apache Thrift (bsc#1263272)\n\nBreaking chahnges introduced in version 12.0.0:\n\n- BREAKING: Removed AngularJS and all deprecated UI Extensions  APIs.\n- BREAKING: Enforced stricter version compatibility checks in plugin CLI install commands.\n- BREAKING: Enabled the failWrongDSUID feature flag by default, which rejects data sources with incorrect UIDs.\n\nOther changes introduced from version 11.6.14+security04 to version 12.4.5 (jsc#PED-16512):\n\n- Add Legal-Review-Notice (bsc#1271327)\n- Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid\n- Analytics: Keep internal dashboard id.\n- Reporting: Correctly apply appSubURL to report settings requests\n- Alerting: Document Grafana HA Alertmanager cluster metrics prefix change.\n- Dependency updates to core plugins and UI libraries.\n- Updates to data source provisioning and dashboard schemas.\n- Introduced dynamic dashboards in public preview.\n- Added a new side toolbar that replaces the second top toolbar to provide additional vertical space.\n- Added the ability to create dashboards from templates using sample data.\n- Revamped the gauge visualization with rounded bars, configurable bar thickness, and endpoint markers.\n- Added support to map one variable to multiple values.\n- Released a completely redesigned logs visualization.\n- Added the ability to export dashboards directly as PNG images.\n- Introduced an interactive learning experience within the Grafana UI.\n- Added a Switch template variable type to quickly toggle between values in queries.\n- Added functionality to style table cells using CSS properties via the field cell option.\n- Added support for Entra Workload Identity to enhance authentication capabilities with federated credentials.\n- Redesigned the alert rule list page.\n- Renamed Mute Timings to Active Time Intervals in Grafana Alerting.\n- Added support for Service Account Impersonation in the BigQuery data source.\n- Introduced the Grafana Advisor in public preview.\n- Introduced a new dashboard schema to replace the original single grid layout.\n- MIGRATION: Triggered a full-table rewrite for the annotation table, which may temporarily increase disk usage.\n","modified":"2026-08-26T18:23:33.844658759Z","published":"2026-08-24T09:23:40Z","related":["CVE-2025-12141","CVE-2025-30153","CVE-2026-21725","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-28374","CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-33382","CVE-2026-39821","CVE-2026-39882","CVE-2026-41607","CVE-2026-42502","CVE-2026-42506"],"upstream":["CVE-2025-12141","CVE-2025-30153","CVE-2026-21725","CVE-2026-25680","CVE-2026-25681","CVE-2026-27136","CVE-2026-28374","CVE-2026-28376","CVE-2026-28379","CVE-2026-28380","CVE-2026-28383","CVE-2026-33376","CVE-2026-33377","CVE-2026-33378","CVE-2026-33380","CVE-2026-33381","CVE-2026-33382","CVE-2026-39821","CVE-2026-39882","CVE-2026-41607","CVE-2026-42502","CVE-2026-42506"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263718-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262187"},{"type":"REPORT","url":"https://bugzilla.suse.com/1263272"},{"type":"REPORT","url":"https://bugzilla.suse.com/1264764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265281"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265282"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265283"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265284"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265285"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265286"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265288"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265290"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266600"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267153"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271327"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271331"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274217"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-12141"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-30153"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-25681"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27136"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28383"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33376"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33377"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33381"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-33382"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39821"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-39882"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-41607"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42502"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42506"}],"affected":[{"package":{"name":"grafana","ecosystem":"SUSE:Linux Enterprise Module for Package Hub 15 SP7","purl":"pkg:rpm/suse/grafana&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"12.4.5-150200.3.91.1"}]}],"ecosystem_specific":{"binaries":[{"grafana":"12.4.5-150200.3.91.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3718-1.json"}}],"schema_version":"1.9.0"}