CVE-2025-8263
Grafana vulnerability analysis and mitigation

Overview

A regular expression denial of service (ReDoS) vulnerability was discovered in the prettier code formatter tool up to version 3.6.2. The vulnerability specifically affects the parseNestedCSS function in the src/language-css/parser-postcss.js file. This vulnerability was initially reported on July 28, 2025, but was later withdrawn by its CNA after further investigation showed it was not a security issue (NVD).

Technical details

The vulnerability was initially assigned a CVSS v3.1 base score with vector string AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L, indicating a network-accessible vulnerability with low attack complexity. The issue was classified under CWE-1333 and CWE-400, relating to inefficient regular expression complexity. The vulnerability specifically affects the parseNestedCSS function's handling of input, which could lead to regular expression processing issues (Rapid7).

Impact

The vulnerability could potentially allow an attacker with access to input source files to induce a denial of service condition in systems running the affected prettier versions. The impact is limited to availability, with no direct effect on confidentiality or integrity of the system (RedHat).

Mitigation and workarounds

As the vulnerability was withdrawn after being determined not to be a security issue, no specific mitigation steps were provided. The initial reports indicated that mitigation options either were not available or did not meet Red Hat Product Security criteria for ease of use and deployment (RedHat).

Additional resources


SourceThis report was generated using AI

Related Grafana vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23950HIGH8.8
  • JavaScriptJavaScript
  • grafana-graphite
NoYesJan 20, 2026
CVE-2026-22610HIGH8.5
  • JavaScriptJavaScript
  • grafana-stackdriver
NoYesJan 10, 2026
CVE-2026-23745HIGH8.2
  • JavaScriptJavaScript
  • nodejs24-devel
NoYesJan 16, 2026
CVE-2026-22029HIGH8
  • JavaScriptJavaScript
  • grafana
NoYesJan 10, 2026
CVE-2025-14505MEDIUM5.6
  • JavaScriptJavaScript
  • grafana-selinux
NoNoJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management