Grafana security advisory (AV26-936)
Canada's Cyber Centre warns Grafana OSS versions 12.3.0 through 13.2.1 are affected by a Geomap MapLibre XSS vulnerability; administrators should apply updates.
The Canadian Centre for Cyber Security issued advisory AV26-936 on September 18, 2026, stating that Grafana is affected by vulnerabilities as of September 17, 2026. Affected versions are Grafana OSS 12.3.0 to 12.4.10, 13.0.0 to 13.08, 13.1.0 to 13.1.5, and 13.2.0 to 13.2.1. The advisory references a Geomap MapLibre cross-site scripting issue and encourages users and administrators to review the linked Grafana security advisories and apply updates as they become available.
- Affected versions span Grafana OSS 12.3.0-12.4.10, 13.0.0-13.08, 13.1.0-13.1.5, 13.2.0-13.2.1
- Referenced issue is a Geomap MapLibre cross-site scripting (XSS) flaw
- Administrators urged to apply updates as they become available
Full article67 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-936
Date: September 18, 2026
As of September 17, 2026, Grafana is affected by vulnerabilities in the following product:
- Grafana OSS
- Version 12.3.0 to 12.4.10
- Version 13.0.0 to 13.08
- Version 13.1.0 to 13.1.5
- Version 13.2.0 to 13.2.1
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/grafana-security-advisory-av26-936