Red Hat Security Advisory: grafana security update
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
Red Hat Enterprise Linux's Grafana packages are affected by multiple security vulnerabilities. CVE-2025-30204 concerns the golang-jwt/jwt library used by Grafana, which allows excessive memory allocation during JWT header parsing. CVE-2025-21613 and CVE-2025-21614 relate to the go-git library, where argument injection via the URL field and denial-of-service via malicious Git server replies are possible. These vulnerabilities affect multiple architectures and versions of Red Hat Enterprise Linux 8 and 9. Red Hat has issued security advisories RHSA-2025:3344 and RHSA-2025:0401 with updated packages to remediate these issues.
Potential Impact
The vulnerabilities could allow an attacker to cause excessive memory allocation potentially leading to denial-of-service conditions or exploit argument injection flaws in the go-git library. This may impact the stability and security of Grafana deployments on affected Red Hat Enterprise Linux systems. The issues have been rated as having a high security impact by Red Hat. No evidence of active exploitation in the wild has been reported.
Mitigation Recommendations
Red Hat has released updated Grafana packages that address these vulnerabilities. Users should apply the security updates provided in Red Hat Enterprise Linux versions 8 and 9 as detailed in advisories RHSA-2025:3344 and RHSA-2025:0401. For detailed update instructions, refer to https://access.redhat.com/articles/11258. Applying these updates will remediate the identified security issues.
Red Hat Security Advisory: grafana security update
Description
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * golang-jwt/jwt: jwt-go allows excessive memory allocation during header parsing (CVE-2025-30204) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Enterprise Linux's Grafana packages are affected by multiple security vulnerabilities. CVE-2025-30204 concerns the golang-jwt/jwt library used by Grafana, which allows excessive memory allocation during JWT header parsing. CVE-2025-21613 and CVE-2025-21614 relate to the go-git library, where argument injection via the URL field and denial-of-service via malicious Git server replies are possible. These vulnerabilities affect multiple architectures and versions of Red Hat Enterprise Linux 8 and 9. Red Hat has issued security advisories RHSA-2025:3344 and RHSA-2025:0401 with updated packages to remediate these issues.
Potential Impact
The vulnerabilities could allow an attacker to cause excessive memory allocation potentially leading to denial-of-service conditions or exploit argument injection flaws in the go-git library. This may impact the stability and security of Grafana deployments on affected Red Hat Enterprise Linux systems. The issues have been rated as having a high security impact by Red Hat. No evidence of active exploitation in the wild has been reported.
Mitigation Recommendations
Red Hat has released updated Grafana packages that address these vulnerabilities. Users should apply the security updates provided in Red Hat Enterprise Linux versions 8 and 9 as detailed in advisories RHSA-2025:3344 and RHSA-2025:0401. For detailed update instructions, refer to https://access.redhat.com/articles/11258. Applying these updates will remediate the identified security issues.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:0401
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-21614"]
Threat ID: 6a1f4e9ee29bf47b50086eaa
Added to database: 06/02/2026, 21:43:58 UTC
Last enriched: 08/14/2026, 22:12:07 UTC
Last updated: 09/10/2026, 19:36:49 UTC
Views: 102
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.