[Git][security-tracker-team/security-tracker][master] auto-nfu: Track the entire Grafana CNA as NFU

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 3 13:15:43 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d63cfd15 by Moritz Muehlenhoff at 2026-09-03T12:15:52+02:00
auto-nfu: Track the entire Grafana CNA as NFU

While src:grafana was packaged briefly, it has been removed eight years
ago and given the quick upstream pace and the complexities of the web UI
it will unlikely come back.

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -470,7 +470,7 @@ CVE-2026-20212 (A vulnerability in the Silicon One integration for Cisco Nexus 9
 CVE-2026-19698 (The GutenKit WordPress plugin before 2.5.1 does not validate or escape ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19475 (An authenticated user with permission to query a SQL data source can b ...)
-	TODO: check
+	NOT-FOR-US: Grafana
 CVE-2026-19219 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, insuffic ...)
 	NOT-FOR-US: Progress Software
 CVE-2026-19117 (Under specific conditions, an attacker can register an attacker-contro ...)
@@ -494,7 +494,7 @@ CVE-2026-14326 (The Timetics WordPress plugin through 1.0.61 does not enforce pe
 CVE-2026-14255 (A maliciously crafted IFC file, when parsed through certain Autodesk p ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-14199 (Only self-managed Grafana instances with Auth Proxy authentication and ...)
-	TODO: check
+	NOT-FOR-US: Grafana
 CVE-2026-12704 (When SAML IdP-initiated login is enabled in Grafana Enterprise, the SA ...)
 	NOT-FOR-US: Grafana Labs
 CVE-2026-10821 (The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize ...)
@@ -6991,7 +6991,7 @@ CVE-2026-19401 (Any remote client can crash a (debugging/non-release build type)
 CVE-2026-19271 (Improper Neutralization of Special Elements used in an LDAP Query ('LD ...)
 	NOT-FOR-US: Liderahenk
 CVE-2026-19197 (A user with organization administrator permissions can delete dashboar ...)
-	TODO: check
+	NOT-FOR-US: Grafana
 CVE-2026-19042 (A command injection vulnerability in TeamViewer Full Client and Host f ...)
 	NOT-FOR-US: TeamViewer
 CVE-2026-18916 (Any remote client can crash a NSD serve child, by throttling the TCP r ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -125,6 +125,8 @@
   cna: GitHub_P
 - reason: Google devices
   cna: Google_Devices
+- reason: Grafana
+  cna: GRAFANA
 - reason: Hanwha Vision
   cna: Hanwha_Vision
 - reason: HCL
@@ -539,14 +541,6 @@
     - cna: Google
     - anyOf:
       - product: Gemini
-- reason: Grafana Labs
-  allOf:
-    - cna: GRAFANA
-    - anyOf:
-      - product: Grafana
-      - product: Grafana Enterprise
-      - product: Grafana OSS
-      - product: Snowflake Datasource
 - reason: Hashicorp products not packaged in Debian
   allOf:
     - cna: HashiCorp



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d63cfd1557554939c4239f89285049690ede3cfa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d63cfd1557554939c4239f89285049690ede3cfa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/22757e4a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list