Grafana security advisory (AV26-860)
Canada's Cyber Centre warned that Grafana Alloy versions through 1.18.1 are affected by CVE-2026-19516 and urged users to apply available updates.
Canada's Cyber Centre issued advisory AV26-860 warning that Grafana Alloy versions prior to or equal to 1.18.1 are affected by CVE-2026-19516. The bulletin directs users and administrators to vendor resources and available patches. No exploitation or severity details are included in the advisory text.
- Affects Grafana Alloy versions prior to or equal to 1.18.1
- Tracked as CVE-2026-19516
- Cyber Centre urges users to apply available updates
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-19516 | A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller als A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also choose the HTTP method, path, and body. Because the destination is not restricted to the configured Grafana instance, a caller can direct requests at internal, loopback, and link-local network services (including metadata endpoints) and read the responses, resulting in server-side request forgery. The fix for CVE-2026-15583 prevented the configured service-account token from being sent to unintended destinations but did not restrict the destinations themselves. NVD description · AI analysis pending | 9.1 | <1% | — | — |
Serial Number: AV26-860 Date: August 28, 2026 As of August 27, 2026, Grafana is affected by a vulnerability in the following product: Alloy Prior to or equal to 1.18.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Grafana: The open and composable observability platform | Grafana Labs CVE-2026-19516 CVE Record
This source does not provide full text. Read it at cyber.gc.ca.