github.com
https://github.com/grafana/grafana CVE-2025-1088
LOW
Very long unicode dashboard title or panel name can hang the frontend
Record summary
CVE-2025-1088 has a selected CVSS score of 2.7 (low).
Description
In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 18, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
GrafanaBrowse Grafana / GrafanaDefault status: unaffected | CVE List | Before 11.6.2 | affected |
github.com/grafana/grafanaBrowse Go / github.com/grafana/grafana | GitHub Advisory | 0.0.1-test to < 11.6.2 · Fixed in 11.6.2 | affected |
| Before 0.0.0-20250521211231-e0ba4b480954 · Fixed in 0.0.0-20250521211231-e0ba4b480954 | affected |
References
3grafana.com
https://grafana.com/security/security-advisories/cve-2025-1088 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-1088