grafana12.11.2
Helm chartThe leading tool for querying and visualizing time series and metrics.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.
Radar Score
- Critical
- 0
- High
- 0
- Medium
- 0
- Low
- 67
- On CISA KEV
- 0
- Exploited (EPSS ≥ 0.1)
- 0
67 findings over 1 of 1 images measured · scored 2 Sept 2026
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
History
Radar Score of 12.11.2, one sample per day, last 90 days. Hover a point for its date and advisory data.
Score moves
A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves
Fewer than two samples so far.
Findings
showing 50 of 67
| Advisory | Package | Fixed in | Contribution | EPSS | Since | Digests |
|---|---|---|---|---|---|---|
| GHSA-mh2q-q3fh-2475 OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification) | go.opentelemetry.io/otel@v1.40.0golang | 1.41.0 | 14/100 | 0.007 (48th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-p4r4-xvrq-gvmc Grafana Tempo has an Uncontrolled Resource Consumption issue | github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cecgolang | 2.8.4 | 14/100 | 0.006 (48th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-6xff-cpcq-vpw2 Grafana Tempo vulnerable to an out-of-memory crash | github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cecgolang | 1.5.1-0.20260303204923-b13f74291d48 | 10/100 | 0.004 (34th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-hfvc-g4fc-pqhx opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | go.opentelemetry.io/otel/sdk@v1.40.0golang | 1.43.0 | 10/100 | 0.003 (17th pct) | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-63073 | openssl@3.5.7-r0apk | 3.5.8-r0 | 10/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-5cv4-jp36-h3mw Go Net HTML parser is vulnerable to denial of service | golang.org/x/net@v0.51.0golang | 0.55.0 | 10/100 | 0.003 (25th pct) | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-75803 | openssl@3.5.7-r0apk | 3.5.8-r0 | 9/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-hrxh-6v49-42gf gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | google.golang.org/grpc@v1.79.3golang | 1.82.1 | 9/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-vp52-pcj8-j9qc gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | google.golang.org/grpc@v1.79.3golang | 1.83.1 | 9/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-ffqx-q65f-36jf Grafana Tempo has Inadequate Encryption Strength | github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cecgolang | 2.10.3 | 9/100 | 0.002 (5th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4981 Crash when handling long CNAME response in net | stdlib@go1.25.7golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4977 Quadratic string concatenation in consumePhrase in net/mail | stdlib@go1.25.7golang | 1.25.10 | 8/100 | 0.008 (54th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4986 Quadratic string concatentation in consumeComment in net/mail | stdlib@go1.25.7golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | golang.org/x/net@v0.51.0golang | 0.53.0 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4918 Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | stdlib@go1.25.7golang | 1.25.10 | 8/100 | 0.008 (53th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4601 Incorrect parsing of IPv6 host literals in net/url | stdlib@go1.25.7golang | 1.25.8 | 8/100 | 0.007 (51th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | stdlib@go1.26.3golang | 1.25.13 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5026 Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | golang.org/x/net@v0.51.0golang | 0.55.0 | 8/100 | 0.007 (50th pct) | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-14456 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-14457 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-18798 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-54874 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-63072 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-63075 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-63076 | openssl@3.5.7-r0apk | 3.5.8-r0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| GHSA-8wv5-x4w7-5gww Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop | github.com/apache/thrift@v0.23.1-0.20260429145742-d2acd3c49e58golang | 0.24.0 | 8/100 | — | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4870 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls | stdlib@go1.25.7golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4947 Unexpected work during chain building in crypto/x509 | stdlib@go1.25.7golang | 1.25.9 | 7/100 | 0.006 (47th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5037 Inefficient candidate hostname parsing in crypto/x509 | stdlib@go1.26.3golang | 1.25.11 | 7/100 | 0.006 (46th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4971 Panic in Dial and LookupPort when handling NUL byte on Windows in net | stdlib@go1.25.7golang | 1.25.10 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5972 Enforce maximum recursion depth in encoding/asn1 | stdlib@go1.26.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-6088 Add recursion depth guard during decode in encoding/xml | stdlib@go1.26.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-6089 Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http | stdlib@go1.26.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-6090 Limit handshake messages we are willing to accept post-handshake in crypto/tls | stdlib@go1.26.3golang | 1.25.13 | 7/100 | 0.006 (45th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5038 Quadratic complexity in WordDecoder.DecodeHeader in mime | stdlib@go1.26.3golang | 1.25.11 | 7/100 | 0.006 (44th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | golang.org/x/net@v0.55.0golang | 0.56.0 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5942 Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage | stdlib@go1.26.3golang | 1.26.6 | 7/100 | 0.005 (44th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-6218 Avoid quadratic complexity in resolvePath in net/url | stdlib@go1.26.3golang | 1.25.13 | 7/100 | 0.005 (42th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5970 Infinite loop on invalid input in golang.org/x/text | golang.org/x/text@v0.37.0golang | 0.39.0 | 7/100 | 0.005 (39th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-6107 Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 | go.etcd.io/etcd/client/pkg/v3@v3.6.9golang | 3.5.33 | 6/100 | 0.004 (33th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4976 ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil | stdlib@go1.25.7golang | 1.25.10 | 6/100 | 0.004 (32th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5856 Invoking Encrypted Client Hello privacy leak in crypto/tls | stdlib@go1.26.3golang | 1.25.12 | 6/100 | 0.004 (31th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4980 Escaper bypass leads to XSS in html/template | stdlib@go1.25.7golang | 1.25.10 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5039 Arbitrary inputs are included in errors without any escaping in net/textproto | stdlib@go1.26.3golang | 1.25.11 | 6/100 | 0.004 (30th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4946 Inefficient policy validation in crypto/x509 | stdlib@go1.25.7golang | 1.25.9 | 6/100 | 0.004 (28th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2022-0646 CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go | github.com/aws/aws-sdk-go@v1.55.8golang | no fix listed | 6/100 | 0.003 (27th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-5158 Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel | go.opentelemetry.io/otel@v1.43.0golang | 1.42.0 | 6/100 | 0.003 (26th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-4603 URLs in meta content attribute actions are not escaped in html/template | stdlib@go1.25.7golang | 1.25.8 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 3fd54ae12146 |
| GO-2026-6303 Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | golang.org/x/crypto@v0.53.0golang | 0.55.0 | 6/100 | 0.003 (25th pct) | 2 Sept 2026 | 3fd54ae12146 |
| ALPINE-CVE-2026-63074 | openssl@3.5.7-r0apk | 3.5.8-r0 | 6/100 | — | 2 Sept 2026 | 3fd54ae12146 |
Workloads and images
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
| Container | Image | Tag | Digest | Radar Score |
|---|---|---|---|---|
| Deployment candidate-grafana | ||||
| grafana | grafana/grafana | 13.2.0 | 3fd54ae12146 | 471 |
Unmeasured images (0)
Every image the render resolved has a scan.