Threats Tagged 'cve-2026-42127'
View all threats tagged with 'cve-2026-42127'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-42127'
Click on any threat for detailed analysis and mitigation recommendations
0 Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377) * grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default (CVE-2026-33376) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via HTML parsing bypass (CVE-2026-27136) * golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681) * golang.org/x/net/html: golang: golang.org/x/net/html: Cross-Site Scripting via unexpected HTML tree rendering (CVE-2026-42502) * grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127) * grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route (CVE-2026-8609) * grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads (CVE-2026-33382) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 09/15/2026, 10:06:12 UTC Added: 08/12/2026, 16:12:05 UTC |
0 The golang packages provide the Go programming language compiler. Security Fix(es): * crypto/x509: Incorrect enforcement of email constraints in crypto/x509 (CVE-2026-27137) * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499) * cmd/go: golang: Go command (cmd/go): Integrity bypass due to checksum validation flaw via malicious module proxy (CVE-2026-42501) * html/template: golang: Go html/template: Cross-Site Scripting via improper URL escaping in meta tag content (CVE-2026-39823) * cmd/go: golang: Go 'go bug' command: Arbitrary file overwrite via symlink attack (CVE-2026-39819) * net/http/internal/http2: golang: golang.org/x/net: Go HTTP/2: Denial of Service via malformed SETTINGS_MAX_FRAME_SIZE frame (CVE-2026-33814) * net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820) * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * net/http/httputil: golang: net/http/httputil: ReverseProxy forwards hidden query parameters, potentially bypassing security controls (CVE-2026-39825) * cmd/go: golang: Go tool pack: Arbitrary file write via malicious archive extraction (CVE-2026-39817) * html/template: golang: html/template: Cross-site scripting due to incorrect script tag escaping (CVE-2026-39826) * golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * net/textproto: golang: Golang net/textproto: Misleading error messages via input injection (CVE-2026-42507) * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) * golang: Go os.Root: Symlink following vulnerability allows directory traversal (CVE-2026-39822) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 08/31/2026, 04:11:57 UTC Added: 05/28/2026, 22:15:02 UTC |
0 Two security vulnerabilities have been identified in Grafana as packaged by Red Hat Enterprise Linux 8. These include a privilege escalation vulnerability via dashboard overwrite (CVE-2026-33377) and a denial of service vulnerability caused by excessive memory allocation from large JSON payloads (CVE-2026-42127). Red Hat has released security updates addressing these issues in Grafana version 9.2.10-32.el8_10.1 for multiple architectures. The update is rated as Important by Red Hat Product Security. Join the discussion | GCVE Database | 08/12/2026, 09:39:03 UTC Added: 09/22/2026, 02:04:25 UTC |
0 A denial of service vulnerability exists in Grafana due to excessive memory allocation triggered by large JSON payloads. This issue is tracked as CVE-2026-42127 and affects Grafana packages distributed with Red Hat Enterprise Linux 9. Red Hat has issued a security advisory with an important severity rating and made updated packages available to address this flaw. Join the discussion | GCVE Database | 08/12/2026, 08:02:13 UTC Added: 09/22/2026, 02:04:25 UTC |
0 A timing attack vulnerability exists in the basicAuth and bearerAuth middlewares of Hono, a component included in Red Hat Hardened Images RPMs. This flaw allows a remote attacker to infer valid credentials by measuring response times due to non-constant-time string comparisons. Red Hat has issued an update including fixed RPMs for grafana12.4 to address this and related vulnerabilities. No known exploits are currently reported in the wild. Join the discussion | GCVE Database | 07/28/2026, 22:54:31 UTC Added: 09/22/2026, 02:04:25 UTC |
0 A timing attack vulnerability exists in the basicAuth and bearerAuth middlewares of the Hono component used in Red Hat Hardened Images RPMs. This flaw allows a remote attacker to infer valid credentials by measuring response times due to non-constant-time string comparisons. The issue is addressed in updated RPM packages for grafana13.1. No known exploits are reported in the wild. The vulnerability has a high severity rating by Red Hat, though no CVSS score is provided. Join the discussion | GCVE Database | 07/28/2026, 22:49:08 UTC Added: 09/22/2026, 02:04:25 UTC |
0 The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability. Join the discussion | CVE Database V5 | 07/22/2026, 00:00:00 UTC Added: 06/22/2026, 17:39:38 UTC |
Showing 1 to 7 of 7 results