CVE-2022-30631
Grafana vulnerability analysis and mitigation

Overview

CVE-2022-30631 is a security vulnerability discovered in Go's compress/gzip package affecting versions before Go 1.17.12 and Go 1.18.4. The vulnerability involves uncontrolled recursion in the Reader.Read method that allows an attacker to cause a panic due to stack exhaustion via an archive containing a large number of concatenated 0-length compressed files (NVD, Go Issue).

Technical details

The vulnerability is classified as CWE-674 (Uncontrolled Recursion) with a CVSS v3.1 Base Score of 7.5 (HIGH). The issue occurs in the Reader.Read implementation within the compress/gzip package, where processing an archive with numerous concatenated empty compressed files could trigger unbounded recursion, leading to stack exhaustion (NVD).

Impact

When exploited, this vulnerability can cause a denial of service through application panic due to stack exhaustion. The attack vector is network-accessible (AV:N) with low attack complexity (AC:L), requiring no privileges (PR:N) or user interaction (UI:N), affecting only availability (A:H) without compromising confidentiality or integrity (NVD).

Mitigation and workarounds

The issue has been fixed in Go versions 1.17.12 and 1.18.4 by replacing recursion with iteration in the Reader.Read implementation. Users are advised to upgrade to these or later versions. The fix was implemented through a patch that modified the handling of concatenated files in the compress/gzip package (Go Patch, Go Announce).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-15284HIGH8.7
  • JavaScriptJavaScript
  • gjs
NoYesDec 29, 2025
CVE-2026-22610HIGH8.5
  • JavaScriptJavaScript
  • grafana-mssql
NoYesJan 10, 2026
CVE-2026-22029HIGH8
  • JavaScriptJavaScript
  • ipa-server
NoYesJan 10, 2026
CVE-2025-68429HIGH7.3
  • JavaScriptJavaScript
  • storybook
NoYesDec 17, 2025
CVE-2025-14505MEDIUM5.6
  • JavaScriptJavaScript
  • polkit-libs
NoNoJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management