CVE-2025-1088: Grafana

Low severity, CVSS 2.7. EPSS: 0.5% chance of exploitation in the next 30 days.

In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

Affected products

  • Grafana Grafana: before 11.6.2 (fixed in 11.6.2)

Published 2025-06-18. Last modified 2026-06-17.