CVE-2025-10630
MEDIUMGrafana-Zabbix < 6.0.0 - Denial of Service via Regex Query ReDoS
Title source: llmDescription
Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring. Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6.0.0.
References (2)
Core 2
Core References
Release Notes release-notes
https://github.com/grafana/grafana-zabbix/releases/tag/v6.0.0
Various Sources vendor-advisory
https://grafana.com/security/security-advisories/cve-2025-10630/
Scores
CVSS v3
4.3
EPSS
0.0032
EPSS Percentile
23.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-20
Status
published
Products (2)
alexanderzobnin/grafana-zabbix
0 - 6.0.0Go
Grafana/grafana-zabbix-plugin
< 6.0.2
Published
Sep 19, 2025
Tracked Since
Feb 18, 2026