Skip to content

grafana

v12.3.7 Security

This release includes 5 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 5 known CVEs

Topics

alerting analytics business-intelligence web data-visualization elasticsearch
+7 more
go grafana influxdb prometheus monitoring mysql postgresql

ReleasePort's take

Moderate signal
editorial:auto 1mo

Grafana v12.3.7 patches CVE-2026-33382 and adds several performance improvements.

Why it matters: CVE‑2026‑33382 is patched; operators should upgrade Grafana core immediately to mitigate the vulnerability (severity 95).

Summary

AI summary

Updates Features and enhancements, https://github.com/filewalkwithme, and https://github.com/grafana/grafana/pull/121558 across a mixed release.

Changes in this release

Security Critical

Patches CVE-2026-33382 vulnerability.

Patches CVE-2026-33382 vulnerability.

Source: llm_adapter@2026-06-09

Confidence: high

Feature Medium

Improves dashboard endpoint performance.

Improves dashboard endpoint performance.

Source: llm_adapter@2026-06-09

Confidence: high

Dependency Low

Updates Docker Alpine base image to 3.23.4.

Updates Docker Alpine base image to 3.23.4.

Source: llm_adapter@2026-06-09

Confidence: high

Dependency Low

Updates Go runtime to version 1.26.3.

Updates Go runtime to version 1.26.3.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Returns 403 instead of 500 for insufficient LibraryPanels permissions.

Returns 403 instead of 500 for insufficient LibraryPanels permissions.

Source: llm_adapter@2026-06-09

Confidence: high

Full changelog

Download page
What's new highlights

Features and enhancements

  • Dashboards: Get annotations and dashboard endpoint performance improvements #121558, @filewalkwithme
  • Docker: Bump Alpine-based images to 3.23.4 #123028, @Proximyst
  • Go: Update version to 1.26.3 #124457, @macabu
  • LibraryPanels: Return 403 instead of 500 for insufficient permissions #123471, @MissingRoberto
  • Security: CVE-2026-33382
  • Security: CVE-2026-42127
  • Security: CVE-2026-42129
  • Security: CVE-2026-10601
  • Security: CVE-2026-8609

Security Fixes

  • CVE-2026-33382
  • CVE-2026-42127
  • CVE-2026-42129
  • CVE-2026-10601
  • CVE-2026-8609

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track grafana

Get notified when new releases ship.

Sign up free

About grafana

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

All releases →

Related context

Related tools

Related CVEs

Beta — feedback welcome: [email protected]