This release includes 7 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
ReleasePort's take
Moderate signalGrafana v12.4.4 patches multiple critical security vulnerabilities.
Why it matters: Patch immediately to mitigate CVE-2026‑9029, CVE-2026‑33382, and other high‑severity flaws affecting Grafana core; all deployments should upgrade now.
Summary
AI summaryBroad release touches Bug fixes, Features and enhancements, https://github.com/adamyeats, and https://github.com/grafana/grafana/pull/120678.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patch security vulnerabilities CVE-2026-9029, CVE-2026-33382, CVE-2026-42127, CVE-2026-42129, CVE-2026-10601, CVE-2026-8609, CVE-2026-8595. Patch security vulnerabilities CVE-2026-9029, CVE-2026-33382, CVE-2026-42127, CVE-2026-42129, CVE-2026-10601, CVE-2026-8609, CVE-2026-8595. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Medium |
Improve dashboard browsing UI for better visibility when zoomed. Improve dashboard browsing UI for better visibility when zoomed. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Low |
Strip tagged path from `tags.name` when Graphite aliasSub wrapping is detected. Strip tagged path from `tags.name` when Graphite aliasSub wrapping is detected. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Low |
Sanitise header values to printable ASCII for gRPC compatibility in plugins. Sanitise header values to printable ASCII for gRPC compatibility in plugins. Source: granite4.1:30b@2026-06-09-audit Confidence: low |
— |
| Dependency | Low |
Update Docker Alpine base image to version 3.23.4. Update Docker Alpine base image to version 3.23.4. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Upgrade Go runtime to version 1.26.3. Upgrade Go runtime to version 1.26.3. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Fix AlertManagerPicker visibility check for Alertmanager datasources. Fix AlertManagerPicker visibility check for Alertmanager datasources. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Treat plugin not‑found errors as “not installed” during fetch. Treat plugin not‑found errors as “not installed” during fetch. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Ensure mixed panels update correctly on time‑range changes with stale upstreams. Ensure mixed panels update correctly on time‑range changes with stale upstreams. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Correct timestamp unit conversion for log events in Jaeger trace view. Correct timestamp unit conversion for log events in Jaeger trace view. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Allow PostgreSQL data source to return results for EXPLAIN queries. Allow PostgreSQL data source to return results for EXPLAIN queries. Source: llm_adapter@2026-06-09 Confidence: high |
— |
Full changelog
Download page
What's new highlights
Features and enhancements
- Browse dashboards: Make elements visible and flow better when zoomed #120678, @aocenas
- Docker: Bump Alpine-based images to 3.23.4 #123027, @Proximyst
- Go: Update version to 1.26.3 #124456, @macabu
- Graphite: Strip tagged path from
tags.namewhenaliasSubwrapping is detected #122619, @adamyeats - LibraryPanels: Return 403 instead of 500 for insufficient permissions #123470, @MissingRoberto
- Plugins: Sanitise header values to printable ASCII for gRPC compatibility #122474, @adamyeats
Bug fixes
- Alerting: Fix AlertManagerPicker visibility to check Alertmanager datasources #124073, @konrad147
- Alerting: Treat not found error when fetching plugins as not installed #122989, @rodrigopk
- DashboardDS: Fix Mixed panels not updating on time-range change with stale upstreams #124893, @ivanortegaalba
- Jaeger: Fix log event timestamp unit conversion in trace view #123711, @ktw4071
- PostgreSQL: Allow sql_engine to return results for EXPLAIN queries #123245, @sdague
- Security: CVE-2026-9029
- Security: CVE-2026-33382
- Security: CVE-2026-42127
- Security: CVE-2026-42129
- Security: CVE-2026-10601
- Security: CVE-2026-8609
- Security: CVE-2026-8595
Security Fixes
- CVE-2026-9029
- CVE-2026-33382
- CVE-2026-42127
- CVE-2026-42129
- CVE-2026-10601
- CVE-2026-8609
- CVE-2026-8595
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About grafana
The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.
Beta — feedback welcome: [email protected]