Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY55 SECURITY RECORDS

grafana

grafana

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

This CVE identity is linked to the Lifecycle record Grafana. Use that record for publisher support phases and retirement dates.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2026-27879 27 Mar 2026 8.0.0 < 11.6.14; 12.0.0 < 12.1.10; 12.2.0 < 12.2.8; 12.3.0 < 12.3.6; 12.4.0 < 12.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-28375 27 Mar 2026 8.1.0 < 11.6.14; 12.0.0 < 12.1.10; 12.2.0 < 12.2.8; 12.3.0 < 12.3.6; 12.4.0 < 12.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-27876 27 Mar 2026 11.6.0 < 11.6.14; 12.0.0 < 12.1.10; 12.2.0 < 12.2.8; 12.3.0 < 12.3.6; 12.4.0 < 12.4.2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-27880 27 Mar 2026 v12.1.0 < v12.1.10; v12.2.0 < v12.2.8; v12.3.0 < v12.3.6; v12.4.0 < v12.4.2 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2026-27877 27 Mar 2026 9.3.0 < 11.6.14; 12.0.0 < 12.1.10; 12.2.0 < 12.2.8; 12.3.0 < 12.3.6; 12.4.0 < 12.4.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2026-21725 25 Feb 2026 v11.0.0 < v12.4.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2025-6197 18 Jul 2025 12.0.x < 12.0.2+security-01; 11.6.x < 11.6.3+security-01; 11.5.x < 11.5.6+security-01; 11.4.x < 11.4.6+security-01; 11.3.x < 11.3.8+security-01 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-6023 18 Jul 2025 12.0.x < 12.0.2+security-01; 11.6.x < 11.6.3+security-01; 11.5.x < 11.5.6+security-01; 11.4.x < 11.4.6+security-01; 11.3.x < 11.3.8+security-01 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-3415 17 Jul 2025 10.4.x < 10.4.19+security-01; 11.2.x < 11.2.10+security-01; 11.3.x < 11.3.7+security-01; 11.4.x < 11.4.5+security-01; 11.5.x < 11.5.5+security-01; 11.6.x < 11.6.2+security-01; 12.0.x < 12.0.1+security-01 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-1088 18 Jun 2025 < 11.6.2 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-3454 2 Jun 2025 11.6.0 < 11.6.0+security-01; 11.5.0 < 11.5.3+security-01; 11.4.0 < 11.4.3+security-01; 11.3.0 < 11.3.5+security-01; 11.2.0 < 11.2.8+security-01; 10.4.0 < 10.4.17+security-01 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-3260 2 Jun 2025 11.6.0 < 11.6.1+security-01 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-3580 23 May 2025 12.0.0 < 12.0.1; 11.6.1 < 11.6.2; 11.5.4 < 11.5.5; 11.4.4 < 11.4.5; 11.3.6 < 11.3.7; 11.2.9 < 11.2.10; 10.4.18 < 10.4.19 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-4123 22 May 2025 10.4.18+security-01 < 10.4.19; 11.2.9+security-01 < 11.2.10; 11.3.6+security-01 < 11.3.7; 11.4.4+security-01 < 11.4.5; 11.5.4+security-01 < 11.5.5; 11.6.1+security-01 < 11.6.2; 12.0.0+security-01 < 12.0.1 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2025-2703 23 Apr 2025 11.6.0 < 11.6.0+security-01; 11.5.0 < 11.5.3+security-01; 11.4.0 < 11.4.3+security-01; 11.3.0 < 11.3.5+security-01; 11.2.0 < 11.2.8+security-01 Users are strongly recommended to upgrade to the latest release of Incoming Goods Suite (>= 1.2.1). Update reference ↗
CVE-2024-11741 31 Jan 2025 11.4.0 < 11.4.1; 11.3.0 < 11.3.3; 11.2.0 < 11.2.6; 11.1.0 < 11.1.11; 10.4.0 < 10.4.15 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-10452 29 Oct 2024 10.4.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-9264 18 Oct 2024 11.0.0 < 11.0.5; 11.1.0 < 11.1.6; 11.2.0 < 11.2.1; 11.0.0 < 11.0.6; 11.1.0 < 11.1.7; 11.2.0 < 11.2.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-8118 26 Sep 2024 8.5.0 < 10.3.10; 10.4.0 < 10.4.9; 11.0.0 < 11.0.5; 11.1.0 < 11.1.6; 11.2.0 < 11.2.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-6322 20 Aug 2024 11.1.0 < 11.1.1; 11.1.2 < 11.1.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2024-1313 26 Mar 2024 9.5.0 < 9.5.18; 10.0.0 < 10.0.13; 10.1.0 < 10.1.9; 10.2.0 < 10.2.6; 10.3.0 < 10.3.5 10.4.0 Update reference ↗
CVE-2024-1442 7 Mar 2024 8.5.0 < 9.5.7; 10.0.0 < 10.0.12; 10.1.0 < 10.1.8; 10.2.0 < 10.2.5; 10.3.0 < 10.3.4 For Red Hat Advanced Cluster Management for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.12/html/install/installing Update reference ↗
CVE-2023-6152 13 Feb 2024 2.5.0 < 9.5.16; 10.0.0 < 10.0.11; 10.1.0 < 10.1.7; 10.2.0 < 10.2.4; 10.3.0 < 10.3.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-3128 22 Jun 2023 9.5.0 < 9.5.4; 9.4.0 < 9.4.13; 9.3.0 < 9.3.16; 9.2.0 < 9.2.20; 6.7.0 < 8.5.27 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-2183 6 Jun 2023 8.0.0 < 8.5.26; 9.0.0 < 9.2.19; 9.3.0 < 9.3.15; 9.4.0 < 9.4.12; 9.5.0 < 9.5.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-2801 6 Jun 2023 9.4.0 < 9.4.12; 9.5.0 < 9.5.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-1387 26 Apr 2023 9.1.0 < 9.2.17; 9.3.0 < 9.3.13; 9.4.0 < 9.5.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-1410 23 Mar 2023 8.0.0 < 8.5.22; 9.0.0 < 9.2.15; 9.3.0 < 9.3.11 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2023-22462 2 Mar 2023 >= 9.2, < 9.2.10; >= 9.3, < 9.3.4 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2023-0594 1 Mar 2023 7.0.0 < 8.5.21; 9.0.0 < 9.2.13; 9.3.0 < 9.3.8 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 and https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5/html-single/upgrade_guide/index For supported configurations, refer to: https://access.redhat.com/articles/1548993 Update reference ↗
CVE-2023-0507 1 Mar 2023 8.1.0 < 8.5.21; 9.0.0 < 9.2.13; 9.3.0 < 9.3.8 Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/2789521 and https://access.redhat.com/documentation/en-us/red_hat_ceph_storage/5/html-single/upgrade_guide/index For supported configurations, refer to: https://access.redhat.com/articles/1548993 Update reference ↗
CVE-2022-23498 3 Feb 2023 >= 8.3.0-beta1, < 9.2.10 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2022-23552 27 Jan 2023 >= 9.0, < 9.2.10; >= 9.3, < 9.3.4; >= 8.1, < 8.5.16 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-39324 27 Jan 2023 < 8.5.16; >= 9.0.0, < 9.2.8 For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) Update reference ↗
CVE-2022-39307 9 Nov 2022 >= v9.0.0-beta1, < 9.2.4; < 8.5.15 For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) Update reference ↗
CVE-2022-39306 9 Nov 2022 < 8.5.15; >= 9.v9.0.0-beta1, < 9.2.4 For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) Update reference ↗
CVE-2022-39328 8 Nov 2022 >= 9.2.0, < 9.2.4 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-39229 13 Oct 2022 >= 9.0.0, < 9.1.8; >= 8.5.0, < 8.5.14 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-39201 13 Oct 2022 >= v5.0.0-beta1, < 8.5.14; >= 9.0.0, < 9.1.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-31130 13 Oct 2022 < 8.5.14; >= 9.0.0, < 9.1.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-31123 13 Oct 2022 < 8.5.14; >= 9.0.0, < 9.1.8 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-36062 22 Sep 2022 < 8.5.13; >= 9.0.0, < 9.0.9; >= 9.1.0, < 9.1.6 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-35957 20 Sep 2022 > 9.0.0, < 9.1.6; < 8.5.13 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2022-31107 15 Jul 2022 >= 5.3, < 8.3.10; >= 8.4.0, < 8.4.10; >= 8.5.0, < 8.5.9; >= 9.0.0, < 9.0.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-31097 15 Jul 2022 >= 9.0.0, < 9.0.3; >= 8.5.0, < 8.5.9; >= 8.4.0, < 8.4.10; >= 8.0.0, < 8.3.10 For details on how to apply this update, see Upgrade a Red Hat Ceph Storage cluster using cephadm in the Red Hat Storage Ceph Upgrade Guide.(https://access.redhat.com/documentation/en-us/red_hat_ceph_storage) Update reference ↗
CVE-2022-29170 20 May 2022 >= 7.4.0-beta1, < 7.5.16; >= 8.0.0, < 8.5.3 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-24812 12 Apr 2022 >= 8.1.0-beta1, < 8.4.6 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-21713 8 Feb 2022 >= 5.0.0-beta1, < 7.5.15; >= 8.0.0, < 8.3.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-21703 8 Feb 2022 >= 3.0-beta1, < 7.5.15; >= 8.0.0, < 8.3.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2022-21702 8 Feb 2022 >= 2.0.0-beta1, < 7.5.15; >= 8.0.0, < 8.3.5 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.