Grafana security advisory (AV26-710)
Serial number: AV26-710 Date: July 16, 2026 On July 15, 2026, Grafana published security advisories to address vulnerabilities in the following products: Grafana MCP Server – version 0.17.1 and prior Grafana Loki – version 3.7.0 and prior The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Grafana MCP server-side request forgery via X-Grafana-URL header Loki detected_fields query limits results in unbounded memory allocation Grafana Blog
CSIRTS triage
- What
- A server-side request forgery vulnerability exists via the X-Grafana-URL header.
- Who is affected
- Users of Grafana MCP Server version 0.17.1 and prior.
- Urgency
- Remediation is necessary to prevent potential exploitation.
- Action
- Update to the latest version as recommended.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Grafana MCP Server
Get an email when a new Grafana MCP Server advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/grafana-security-advisory-av26-710
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-155830.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
- Low exploitation riskCVE-2026-217290.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15583 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-21729 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Grafana Loki: Vulnerability allows Denial of Servicecert-bund
- highCVE-2026-21729: Loki queries with large limits can cause large memory allocations which can impact the availab…nvd
- highCVE-2026-15583: A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfi…nvd
More from Canadian Centre for Cyber Security
- unknownGoogle security advisory (AV26-768)2026-07-31
- unknownRails security advisory (AV26-767)2026-07-31
- unknownSolarWinds security advisory (AV26-766)2026-07-31
- unknownGladinet security advisory (AV26-765)2026-07-30
- unknownPHP Group security advisory (AV26-764)2026-07-30