An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected.
Metrics
Affected Vendors & Products
References
History
Thu, 03 Sep 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana grafana Grafana microsoft Sql Server Datasource Grafana mysql Datasource Grafana postgresql Datasource |
|
| Vendors & Products |
Grafana
Grafana grafana Grafana microsoft Sql Server Datasource Grafana mysql Datasource Grafana postgresql Datasource |
Thu, 03 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | CVE-2026-19475 CVE Record | SQL Data Source Plugin: OOM DoS via $__timeGroup macro |
Wed, 02 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 |
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authenticated user with permission to query a SQL data source can bypass the fix for CVE-2026-33375 by injecting the timeGroup macro through a WHERE clause, which Grafana's regex-based macro parsing does not reject. Evaluating the injected macro causes uncontrolled memory consumption that can terminate the Grafana server process, resulting in a denial of service. The Microsoft SQL Server, PostgreSQL, and MySQL data sources are affected. | |
| Title | CVE-2026-19475 CVE Record | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published: 2026-09-02T15:56:33.568Z
Updated: 2026-09-03T08:08:02.649Z
Reserved: 2026-08-10T14:51:01.083Z
Link: CVE-2026-19475
Updated: 2026-09-02T18:01:00.390Z
Status : Awaiting Analysis
Published: 2026-09-02T16:17:15.120
Modified: 2026-09-03T16:37:52.170
Link: CVE-2026-19475
No data.