Alpine: multiple grafana packages: security update to 12.4.4-r0

medium Tenable Cloud Security Plugin ID 443182

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's
XYZ tile layer via a template variable. The script then executes in the browser of any user who views the
affected dashboard (stored cross-site scripting). (CVE-2026-9029)

- A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious
field name that executes as a script in the browser of any user who views the dashboard (stored cross-site
scripting). (CVE-2026-8595)

- An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing
unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of
service). (CVE-2026-8609)

- A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source
plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data
source credentials, leak internal responses, or trigger administrative actions on the configured backend.
(CVE-2026-10601)

Solution

Update the grafana library and its related packages to version 12.4.4-r0 or later.

See Also

https://security.alpinelinux.org/vuln/CVE-2026-10601

https://security.alpinelinux.org/vuln/CVE-2026-33382

https://security.alpinelinux.org/vuln/CVE-2026-42127

https://security.alpinelinux.org/vuln/CVE-2026-42129

https://security.alpinelinux.org/vuln/CVE-2026-8595

https://security.alpinelinux.org/vuln/CVE-2026-8609

https://security.alpinelinux.org/vuln/CVE-2026-9029

Plugin Details

Severity: Medium

ID: 443182

Version: Revision 1.7

Type: Local

Published: 6/13/2026

Updated: 7/14/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51.19

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2026-9029

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Reference Information

CVE: CVE-2026-10601, CVE-2026-33382, CVE-2026-42127, CVE-2026-42129, CVE-2026-8595, CVE-2026-8609, CVE-2026-9029