CVE-2025-1088

LOW

Grafana < 11.6.2 - Denial of Service via Excessively Long Dashboard Title or Panel Name

Title source: llm
STIX 2.1

Description

In Grafana, an excessively long dashboard title or panel name will cause Chromium browsers to become unresponsive due to Improper Input Validation vulnerability in Grafana. This issue affects Grafana: before 11.6.2 and is fixed in 11.6.2 and higher.

References (1)

Core 1

Scores

CVSS v3 2.7
EPSS 0.0039
EPSS Percentile 31.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (2)
Grafana/Grafana < 11.6.2
grafana/grafana 0.0.1-test - 11.6.2Go
Published Jun 18, 2025
Tracked Since Feb 18, 2026