Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6.0.0.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-30280 | Grafana-Zabbix ReDoS vulnerability |
Github GHSA |
GHSA-g4rr-88fc-26fj | Grafana-Zabbix ReDoS vulnerability |
Mon, 22 Sep 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana grafana Zabbix Zabbix zabbix |
|
| Vendors & Products |
Grafana
Grafana grafana Zabbix Zabbix zabbix |
Fri, 19 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 19 Sep 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Grafana is an open-source platform for monitoring and observability. Grafana-Zabbix is a plugin for Grafana allowing to visualize monitoring data from Zabbix and create dashboards for analyzing metrics and realtime monitoring. Versions 5.2.1 and below contained a ReDoS vulnerability via user-supplied regex query which could causes CPU usage to max out. This vulnerability is fixed in version 6.0.0. | |
| Title | Regex DoS in Grafana Zabbix Plugin | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2025-09-24T13:57:31.465Z
Reserved: 2025-09-17T12:11:12.323Z
Link: CVE-2025-10630
Updated: 2025-09-19T11:45:39.559Z
Status : Awaiting Analysis
Published: 2025-09-19T10:15:34.730
Modified: 2025-09-19T16:00:27.847
Link: CVE-2025-10630
No data.
OpenCVE Enrichment
Updated: 2025-09-22T10:06:29Z
EUVD
Github GHSA