Home

Description

Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring.  Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6.0.0.

PUBLISHED Reserved 2025-09-17 | Published 2025-09-19 | Updated 2025-09-24 | Assigner GRAFANA




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Problem types

CWE-20 Improper Input Validation

Product status

Default status
affected

Any version before 6.0.2
affected

Credits

jub0bs finder

References

grafana.com/security/security-advisories/cve-2025-10630/ vendor-advisory

github.com/grafana/grafana-zabbix/releases/tag/v6.0.0 release-notes

cve.org (CVE-2025-10630)

nvd.nist.gov (CVE-2025-10630)

Download JSON