grafana12.11.2

Helm chart
grafana-community repositoryon Artifact Hub 45#107 by starsverified publisher

The leading tool for querying and visualizing time series and metrics.

version 12.11.2kube ^1.25.0-0app version 13.2.0
README badge
[![Radar Score](https://charts.stackradar.io/badge/grafana-community/grafana.svg)](https://charts.stackradar.io/charts/grafana-community/grafana)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

Radar Score

471
worst finding Low
Critical
0
High
0
Medium
0
Low
67
On CISA KEV
0
Exploited (EPSS ≥ 0.1)
0

67 findings over 1 of 1 images measured · scored 2 Sept 2026

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

History

Radar Score of 12.11.2, one sample per day, last 90 days. Hover a point for its date and advisory data.

2 Sept 2026 · Radar Score 471 · OSV as of 2 Sept 2026
history since 2 Sept 2026

Score moves

A score can move without the chart changing: the advisory data behind every finding is refreshed daily. Each move lists which inputs changed. Why a score moves

Fewer than two samples so far.

Findings

67 distinct across the version’s images

AdvisoryPackageFixed inContributionEPSSSinceDigests
GHSA-mh2q-q3fh-2475

OpenTelemetry-Go: multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)

go.opentelemetry.io/otel@v1.40.0golang1.41.014/1000.007 (48th pct)2 Sept 20263fd54ae12146
GHSA-p4r4-xvrq-gvmc

Grafana Tempo has an Uncontrolled Resource Consumption issue

github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cecgolang2.8.414/1000.006 (48th pct)2 Sept 20263fd54ae12146
GHSA-6xff-cpcq-vpw2

Grafana Tempo vulnerable to an out-of-memory crash

github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cecgolang1.5.1-0.20260303204923-b13f74291d4810/1000.004 (34th pct)2 Sept 20263fd54ae12146
GHSA-hfvc-g4fc-pqhx

opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking

go.opentelemetry.io/otel/sdk@v1.40.0golang1.43.010/1000.003 (17th pct)2 Sept 20263fd54ae12146
ALPINE-CVE-2026-63073openssl@3.5.7-r0apk3.5.8-r010/1002 Sept 20263fd54ae12146
GHSA-5cv4-jp36-h3mw

Go Net HTML parser is vulnerable to denial of service

golang.org/x/net@v0.51.0golang0.55.010/1000.003 (25th pct)2 Sept 20263fd54ae12146
ALPINE-CVE-2026-75803openssl@3.5.7-r0apk3.5.8-r09/1002 Sept 20263fd54ae12146
GHSA-hrxh-6v49-42gf

gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities

google.golang.org/grpc@v1.79.3golang1.82.19/1002 Sept 20263fd54ae12146
GHSA-vp52-pcj8-j9qc

gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation

google.golang.org/grpc@v1.79.3golang1.83.19/1002 Sept 20263fd54ae12146
GHSA-ffqx-q65f-36jf

Grafana Tempo has Inadequate Encryption Strength

github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cecgolang2.10.39/1000.002 (5th pct)2 Sept 20263fd54ae12146
GO-2026-4981

Crash when handling long CNAME response in net

stdlib@go1.25.7golang1.25.108/1000.008 (54th pct)2 Sept 20263fd54ae12146
GO-2026-4977

Quadratic string concatenation in consumePhrase in net/mail

stdlib@go1.25.7golang1.25.108/1000.008 (54th pct)2 Sept 20263fd54ae12146
GO-2026-4986

Quadratic string concatentation in consumeComment in net/mail

stdlib@go1.25.7golang1.25.108/1000.008 (53th pct)2 Sept 20263fd54ae12146
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

golang.org/x/net@v0.51.0golang0.53.08/1000.008 (53th pct)2 Sept 20263fd54ae12146
GO-2026-4918

Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

stdlib@go1.25.7golang1.25.108/1000.008 (53th pct)2 Sept 20263fd54ae12146
GO-2026-4601

Incorrect parsing of IPv6 host literals in net/url

stdlib@go1.25.7golang1.25.88/1000.007 (51th pct)2 Sept 20263fd54ae12146
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

stdlib@go1.26.3golang1.25.138/1000.007 (50th pct)2 Sept 20263fd54ae12146
GO-2026-5026

Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna

golang.org/x/net@v0.51.0golang0.55.08/1000.007 (50th pct)2 Sept 20263fd54ae12146
ALPINE-CVE-2026-14456openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
ALPINE-CVE-2026-14457openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
ALPINE-CVE-2026-18798openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
ALPINE-CVE-2026-54874openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
ALPINE-CVE-2026-63072openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
ALPINE-CVE-2026-63075openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
ALPINE-CVE-2026-63076openssl@3.5.7-r0apk3.5.8-r08/1002 Sept 20263fd54ae12146
GHSA-8wv5-x4w7-5gww

Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

github.com/apache/thrift@v0.23.1-0.20260429145742-d2acd3c49e58golang0.24.08/1002 Sept 20263fd54ae12146
GO-2026-4870

Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

stdlib@go1.25.7golang1.25.97/1000.006 (47th pct)2 Sept 20263fd54ae12146
GO-2026-4947

Unexpected work during chain building in crypto/x509

stdlib@go1.25.7golang1.25.97/1000.006 (47th pct)2 Sept 20263fd54ae12146
GO-2026-5037

Inefficient candidate hostname parsing in crypto/x509

stdlib@go1.26.3golang1.25.117/1000.006 (46th pct)2 Sept 20263fd54ae12146
GO-2026-4971

Panic in Dial and LookupPort when handling NUL byte on Windows in net

stdlib@go1.25.7golang1.25.107/1000.006 (45th pct)2 Sept 20263fd54ae12146
GO-2026-5972

Enforce maximum recursion depth in encoding/asn1

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 20263fd54ae12146
GO-2026-6088

Add recursion depth guard during decode in encoding/xml

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 20263fd54ae12146
GO-2026-6089

Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 20263fd54ae12146
GO-2026-6090

Limit handshake messages we are willing to accept post-handshake in crypto/tls

stdlib@go1.26.3golang1.25.137/1000.006 (45th pct)2 Sept 20263fd54ae12146
GO-2026-5038

Quadratic complexity in WordDecoder.DecodeHeader in mime

stdlib@go1.26.3golang1.25.117/1000.006 (44th pct)2 Sept 20263fd54ae12146
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

golang.org/x/net@v0.55.0golang0.56.07/1000.005 (44th pct)2 Sept 20263fd54ae12146
GO-2026-5942

Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage

stdlib@go1.26.3golang1.26.67/1000.005 (44th pct)2 Sept 20263fd54ae12146
GO-2026-6218

Avoid quadratic complexity in resolvePath in net/url

stdlib@go1.26.3golang1.25.137/1000.005 (42th pct)2 Sept 20263fd54ae12146
GO-2026-5970

Infinite loop on invalid input in golang.org/x/text

golang.org/x/text@v0.37.0golang0.39.07/1000.005 (39th pct)2 Sept 20263fd54ae12146
GO-2026-6107

Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3

go.etcd.io/etcd/client/pkg/v3@v3.6.9golang3.5.336/1000.004 (33th pct)2 Sept 20263fd54ae12146
GO-2026-4976

ReverseProxy forwards queries with more than urlmaxqueryparams parameters in net/http/httputil

stdlib@go1.25.7golang1.25.106/1000.004 (32th pct)2 Sept 20263fd54ae12146
GO-2026-5856

Invoking Encrypted Client Hello privacy leak in crypto/tls

stdlib@go1.26.3golang1.25.126/1000.004 (31th pct)2 Sept 20263fd54ae12146
GO-2026-4980

Escaper bypass leads to XSS in html/template

stdlib@go1.25.7golang1.25.106/1000.004 (30th pct)2 Sept 20263fd54ae12146
GO-2026-5039

Arbitrary inputs are included in errors without any escaping in net/textproto

stdlib@go1.26.3golang1.25.116/1000.004 (30th pct)2 Sept 20263fd54ae12146
GO-2026-4946

Inefficient policy validation in crypto/x509

stdlib@go1.25.7golang1.25.96/1000.004 (28th pct)2 Sept 20263fd54ae12146
GO-2022-0646

CBC padding oracle issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

github.com/aws/aws-sdk-go@v1.55.8golangno fix listed6/1000.003 (27th pct)2 Sept 20263fd54ae12146
GO-2026-5158

Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel

go.opentelemetry.io/otel@v1.43.0golang1.42.06/1000.003 (26th pct)2 Sept 20263fd54ae12146
GO-2026-4603

URLs in meta content attribute actions are not escaped in html/template

stdlib@go1.25.7golang1.25.86/1000.003 (25th pct)2 Sept 20263fd54ae12146
GO-2026-6303

Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh

golang.org/x/crypto@v0.53.0golang0.55.06/1000.003 (25th pct)2 Sept 20263fd54ae12146
ALPINE-CVE-2026-63074openssl@3.5.7-r0apk3.5.8-r06/1002 Sept 20263fd54ae12146
GO-2026-4982

Bypass of meta content URL escaping causes XSS in html/template

stdlib@go1.25.7golang1.25.106/1000.003 (24th pct)2 Sept 20263fd54ae12146
GO-2026-6091

Fix Javascript regexp context tracking in html/template

stdlib@go1.26.3golang1.25.136/1000.003 (23th pct)2 Sept 20263fd54ae12146
GO-2026-4864

TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix

stdlib@go1.25.7golang1.25.96/1000.003 (21th pct)2 Sept 20263fd54ae12146
GO-2026-4865

JsBraceDepth Context Tracking Bugs (XSS) in html/template

stdlib@go1.25.7golang1.25.96/1000.003 (21th pct)2 Sept 20263fd54ae12146
GO-2026-4869

Unbounded allocation for old GNU sparse in archive/tar

stdlib@go1.25.7golang1.25.96/1000.003 (21th pct)2 Sept 20263fd54ae12146
GO-2026-5025

Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.51.0golang0.55.05/1000.002 (14th pct)2 Sept 20263fd54ae12146
GO-2026-4970

Root escape via symlink plus trailing slash in os

stdlib@go1.26.3golang1.25.125/1000.002 (14th pct)2 Sept 20263fd54ae12146
GO-2022-0635

In-band key negotiation issue in AWS S3 Crypto SDK for golang in github.com/aws/aws-sdk-go

github.com/aws/aws-sdk-go@v1.55.8golangno fix listed5/1000.002 (14th pct)2 Sept 20263fd54ae12146
GO-2026-5027

Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html

golang.org/x/net@v0.51.0golang0.55.05/1000.002 (13th pct)2 Sept 20263fd54ae12146
GO-2026-5029

Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html

golang.org/x/net@v0.51.0golang0.55.05/1000.002 (13th pct)2 Sept 20263fd54ae12146
GO-2026-5030

Invoking duplicate attributes can cause XSS in golang.org/x/net/html

golang.org/x/net@v0.51.0golang0.55.05/1000.002 (13th pct)2 Sept 20263fd54ae12146
GO-2026-4602

FileInfo can escape from a Root in os

stdlib@go1.25.7golang1.25.85/1000.002 (10th pct)2 Sept 20263fd54ae12146
GO-2026-5024

Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows

golang.org/x/sys@v0.41.0golang0.44.04/1000.001 (2th pct)2 Sept 20263fd54ae12146
GO-2026-5841

OOB read in github.com/klauspost/compress/s2

github.com/klauspost/compress@v1.18.5golang1.18.74/1002 Sept 20263fd54ae12146
GO-2026-5932

The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues

golang.org/x/crypto@v0.53.0golangno fix listed4/1002 Sept 20263fd54ae12146
GO-2026-6061

Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

google.golang.org/grpc@v1.79.3golang1.82.14/1002 Sept 20263fd54ae12146
GO-2026-6094

JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go

github.com/google/cel-go@v0.29.0golang0.30.04/1002 Sept 20263fd54ae12146

Workloads and images

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

ContainerImageTagDigestRadar Score
Deployment candidate-grafana
grafanagrafana/grafana13.2.03fd54ae12146471

Unmeasured images (0)

Every image the render resolved has a scan.

Indexed versions

The latest version and the previous major, as selected nightly from the repository’s index.

VersionApp versionRadar ScoreBandMeasuredRender
13.0.1latest13.2.00 / 1rendered 2 Sept 2026
12.11.2previous major13.2.0471Low1 / 1rendered 2 Sept 2026

helm v3.16.4 · syft 1.42.1 · rendered 2 Sept 2026 · scanned 2 Sept 2026 · advisories as of 2 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.