Record summary

CVE-2025-41117 has a selected CVSS score of 6.8 (medium).

Description

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field. Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 13, 2026 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List12.2.0 to < 12.2.4+security-01affected
12.3.0 to < 12.3.2+security-01affected

Default status: unaffected

CVE List12.2.0 to < 12.2.4+security-01affected
12.3.0 to < 12.3.2+security-01affected

github.com/grafana/grafana

Browse Go / github.com/grafana/grafana
GitHub Advisory12.2.0 to < 12.2.5 · Fixed in 12.2.5affected
12.3.0 to < 12.3.3 · Fixed in 12.3.3affected

References

7