This release includes 5 security fixes for security teams reviewing exposed deployments.
Topics
+7 more
ReleasePort's take
Moderate signalGrafana v12.3.7 patches CVE-2026-33382 and adds several performance improvements.
Why it matters: CVE‑2026‑33382 is patched; operators should upgrade Grafana core immediately to mitigate the vulnerability (severity 95).
Summary
AI summaryUpdates Features and enhancements, https://github.com/filewalkwithme, and https://github.com/grafana/grafana/pull/121558 across a mixed release.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Security | Critical |
Patches CVE-2026-33382 vulnerability. Patches CVE-2026-33382 vulnerability. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Feature | Medium |
Improves dashboard endpoint performance. Improves dashboard endpoint performance. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Updates Docker Alpine base image to 3.23.4. Updates Docker Alpine base image to 3.23.4. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Dependency | Low |
Updates Go runtime to version 1.26.3. Updates Go runtime to version 1.26.3. Source: llm_adapter@2026-06-09 Confidence: high |
— |
| Bugfix | Medium |
Returns 403 instead of 500 for insufficient LibraryPanels permissions. Returns 403 instead of 500 for insufficient LibraryPanels permissions. Source: llm_adapter@2026-06-09 Confidence: high |
— |
Full changelog
Download page
What's new highlights
Features and enhancements
- Dashboards: Get annotations and dashboard endpoint performance improvements #121558, @filewalkwithme
- Docker: Bump Alpine-based images to 3.23.4 #123028, @Proximyst
- Go: Update version to 1.26.3 #124457, @macabu
- LibraryPanels: Return 403 instead of 500 for insufficient permissions #123471, @MissingRoberto
- Security: CVE-2026-33382
- Security: CVE-2026-42127
- Security: CVE-2026-42129
- Security: CVE-2026-10601
- Security: CVE-2026-8609
Security Fixes
- CVE-2026-33382
- CVE-2026-42127
- CVE-2026-42129
- CVE-2026-10601
- CVE-2026-8609
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About grafana
The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.
Beta — feedback welcome: [email protected]