DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-6jcw-php5-5c2j

Package

grafana-11.6

Component

grafana-11.6

Latest update

Pending upstream fix

Aliases

Severity

Unknown
Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-12141

Updates

Status

Pending upstream fix

Impact

CVE-2025-12141 (Information Leakage in Grafana Alerting) is a vulnerability in the Grafana product itself, scanner-flagged at the apk component level. Per Grafana's vendor advisory (https://grafana.com/security/security-advisories/cve-2025-12141/), impacted versions are >8.0.0 <=12.3.0; the fix is in versions >12.3.0 (Grafana 12.4.0+). Grafana has not published a backport patch for the 11.6.x line, so the 11.6 stream cannot remediate this without an upstream-supplied fix. CVSS 1.3 (Low). NVD: https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-12141

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.