INFSA-2025:7475: grafana security update
Information about definition
Identificator: INFSA-2025:7475
Type: security
Release date: 2025-07-15 19:46:51 UTC
Information about package
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.
Vulnerabilities description
- CVE-2025-30204
A flaw was found in the golang-jwt implementation of JSON Web Tokens (JWT). In affected versions, a malicious request with specially crafted Authorization header data may trigger an excessive consumption of resources on the host system. This issue can cause significant performance degradation or an application crash, leading to a denial of service.
Severity level
CVE | Score CVSS 2.0 | Score CVSS 3.x | Score CVSS 4.0 |
---|
Updated packages