Skip to content

grafana

v12.4.4 Security

This release includes 7 security fixes for security teams reviewing exposed deployments.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 7 known CVEs

Topics

alerting analytics business-intelligence web data-visualization elasticsearch
+7 more
go grafana influxdb prometheus monitoring mysql postgresql

ReleasePort's take

Moderate signal
editorial:auto 1mo

Grafana v12.4.4 patches multiple critical security vulnerabilities.

Why it matters: Patch immediately to mitigate CVE-2026‑9029, CVE-2026‑33382, and other high‑severity flaws affecting Grafana core; all deployments should upgrade now.

Summary

AI summary

Broad release touches Bug fixes, Features and enhancements, https://github.com/adamyeats, and https://github.com/grafana/grafana/pull/120678.

Changes in this release

Security Critical

Patch security vulnerabilities CVE-2026-9029, CVE-2026-33382, CVE-2026-42127, CVE-2026-42129, CVE-2026-10601, CVE-2026-8609, CVE-2026-8595.

Patch security vulnerabilities CVE-2026-9029, CVE-2026-33382, CVE-2026-42127, CVE-2026-42129, CVE-2026-10601, CVE-2026-8609, CVE-2026-8595.

Source: llm_adapter@2026-06-09

Confidence: high

Feature Medium

Improve dashboard browsing UI for better visibility when zoomed.

Improve dashboard browsing UI for better visibility when zoomed.

Source: llm_adapter@2026-06-09

Confidence: high

Feature Low

Strip tagged path from `tags.name` when Graphite aliasSub wrapping is detected.

Strip tagged path from `tags.name` when Graphite aliasSub wrapping is detected.

Source: llm_adapter@2026-06-09

Confidence: high

Feature Low

Sanitise header values to printable ASCII for gRPC compatibility in plugins.

Sanitise header values to printable ASCII for gRPC compatibility in plugins.

Source: granite4.1:30b@2026-06-09-audit

Confidence: low

Dependency Low

Update Docker Alpine base image to version 3.23.4.

Update Docker Alpine base image to version 3.23.4.

Source: llm_adapter@2026-06-09

Confidence: high

Dependency Low

Upgrade Go runtime to version 1.26.3.

Upgrade Go runtime to version 1.26.3.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Fix AlertManagerPicker visibility check for Alertmanager datasources.

Fix AlertManagerPicker visibility check for Alertmanager datasources.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Treat plugin not‑found errors as “not installed” during fetch.

Treat plugin not‑found errors as “not installed” during fetch.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Ensure mixed panels update correctly on time‑range changes with stale upstreams.

Ensure mixed panels update correctly on time‑range changes with stale upstreams.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Correct timestamp unit conversion for log events in Jaeger trace view.

Correct timestamp unit conversion for log events in Jaeger trace view.

Source: llm_adapter@2026-06-09

Confidence: high

Bugfix Medium

Allow PostgreSQL data source to return results for EXPLAIN queries.

Allow PostgreSQL data source to return results for EXPLAIN queries.

Source: llm_adapter@2026-06-09

Confidence: high

Full changelog

Download page
What's new highlights

Features and enhancements

Bug fixes

  • Alerting: Fix AlertManagerPicker visibility to check Alertmanager datasources #124073, @konrad147
  • Alerting: Treat not found error when fetching plugins as not installed #122989, @rodrigopk
  • DashboardDS: Fix Mixed panels not updating on time-range change with stale upstreams #124893, @ivanortegaalba
  • Jaeger: Fix log event timestamp unit conversion in trace view #123711, @ktw4071
  • PostgreSQL: Allow sql_engine to return results for EXPLAIN queries #123245, @sdague
  • Security: CVE-2026-9029
  • Security: CVE-2026-33382
  • Security: CVE-2026-42127
  • Security: CVE-2026-42129
  • Security: CVE-2026-10601
  • Security: CVE-2026-8609
  • Security: CVE-2026-8595

Security Fixes

  • CVE-2026-9029
  • CVE-2026-33382
  • CVE-2026-42127
  • CVE-2026-42129
  • CVE-2026-10601
  • CVE-2026-8609
  • CVE-2026-8595

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track grafana

Get notified when new releases ship.

Sign up free

About grafana

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

All releases →

Related context

Related tools

Related CVEs

Beta — feedback welcome: [email protected]