CVE-2022-32189
Grafana vulnerability analysis and mitigation

Overview

CVE-2022-32189 is a vulnerability discovered in Go's math/big package that affects versions before 1.17.13 and 1.18.5. The vulnerability involves a panic condition that can occur in Float.GobDecode and Rat.GobDecode functions when processing too-short encoded messages (NVD, MITRE).

Technical details

The vulnerability occurs when Float.GobDecode and Rat.GobDecode functions in the math/big package attempt to process encoded messages that are too short, leading to an index out of range panic. The issue has been assigned a CVSS 3.1 base score of 7.5 (High), with attack vector being Network, attack complexity Low, and requiring no privileges or user interaction (Ubuntu).

Impact

The vulnerability can potentially lead to a denial of service condition when processing malformed input. When exploited, it causes the application to panic, affecting the availability of the service (Go Issue).

Mitigation and workarounds

The vulnerability has been fixed in Go versions 1.17.13 and 1.18.5. The fix involves adding proper buffer length checks before indexing slices in Float.GobDecode and Rat.GobDecode functions. Users are advised to upgrade to these patched versions or later (Go Announce).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-41115CRITICAL10
  • GrafanaGrafana
  • cpe:2.3:a:grafana:grafana
NoYesNov 21, 2025
CVE-2025-66031HIGH8.7
  • JavaScriptJavaScript
  • kubeflow-pipelines
NoYesNov 26, 2025
CVE-2025-66412HIGH8.5
  • JavaScriptJavaScript
  • grafana-influxdb
NoYesDec 01, 2025
CVE-2025-66035HIGH7.7
  • JavaScriptJavaScript
  • grafana-mssql
NoYesNov 26, 2025
CVE-2025-61725HIGH7.5
  • cAdvisorcAdvisor
  • scorecard
NoYesOct 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management