CVE-2026-19475: Grafana OSS
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Affected products
- Grafana Grafana OSS: from 11.6.0, up to and including 11.6.16; from 12.0.0, up to and including 12.0.10; from 12.1.0, up to and including 12.1.10; from 12.2.0, up to and including 12.2.10; from 12.3.0, up to and including 12.3.11; from 12.4.0, up to and including 12.4.9; …
- Grafana Microsoft SQL Server Datasource: from 13.0.0, up to and including 13.0.1
- Grafana MySQL Datasource: from 13.0.0, up to and including 13.0.2
- Grafana PostgreSQL Datasource: from 13.0.0, up to and including 13.0.1
Published 2026-09-02. Last modified 2026-09-03.