Known vulnerabilities in grafana-pcp (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:grafana-pcp_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 20
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting grafana-pcp (Red Hat package) grafana-pcp (Red Hat package) is affected by 20 known vulnerabilities: 1 high, 18 medium, 1 low Critical High Medium Low

Vulnerabilities (20)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140607 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-32282
CWE-367 Low
No
No
5.1.1-5.el9_2.1, 5.1.1-14.el8_10, 5.1.1-14.el9_6, 5.1.1-14.el9_7, 5.2.2-6.el10_0 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 49 more
#VU140600 - Improper input validation
CVE-2026-32281
CWE-20 Medium
No
No
5.1.1-5.el9_2.1 31.07.2026 SB2026073125
SB2026073183
SB2026073184
and 33 more
#VU140599 - Resource exhaustion
CVE-2026-32280
CWE-400 Medium
No
No
5.1.1-5.el9_2.1, 5.1.1-14.el8_10, 5.1.1-14.el9_6, 5.2.2-6.el10_0 31.07.2026 SB2026073125
SB2026073160
SB2026073161
and 64 more
#VU136680 - Dependency on Vulnerable Third-Party Component
CVE-2026-32283
CWE-1395 Medium
No
No
5.1.1-5.el9_2.1, 5.1.1-14.el8_10, 5.1.1-14.el9_6, 5.1.1-14.el9_7, 5.2.2-6.el10_0, 5.3.0-4.el10_1 02.07.2026 SB2026070218
SB2026070239
SB2026070240
and 59 more
#VU124118 - Improper input validation
CVE-2026-25679
CWE-20 Medium
No
No
3.0.2-4.el8_4, 3.2.0-4.el8_6, 3.2.0-6.el8_8, 3.2.0-6.el9_0, 5.1.1-5.el9_2, 5.1.1-13.el9_6, 5.1.1-13.el9_7, 5.2.2-5.el10_0, 5.3.0-3.el10_1 19.03.2026 SB2026031903
SB2026031904
SB2026031905
and 127 more
#VU124034 - Resource exhaustion
CVE-2025-61726
CWE-400 Medium
No
No
3.0.2-3.el8_4, 3.2.0-3.el8_6, 3.2.0-5.el8_8, 3.2.0-5.el9_0, 5.1.1-4.el9_2, 5.1.1-6.el9_4, 5.1.1-12.el8_10, 5.2.2-4.el10_0, 5.3.0-2.el10_1 16.03.2026 SB2026031636
SB2026031637
SB2026031638
and 140 more
#VU123129 - Improper Certificate Validation
CVE-2025-68121
CWE-295 High
No
No
5.1.1-5.el9_2.1, 5.1.1-12.el8_10, 5.2.2-4.el10_0, 5.3.0-2.el10_1 23.02.2026 SB2026022333
SB2026030334
SB2026030343
and 112 more
#VU121009 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\')
CVE-2025-13204
CWE-1321 Medium
No
No
1.0.5-5.el8_2 07.01.2026 SB2026010710
SB2026010714
SB2026012038
#VU119235 - Resource exhaustion
CVE-2025-61729
CWE-400 Medium
No
No
3.0.2-3.el8_4, 3.2.0-3.el8_6, 3.2.0-5.el8_8, 3.2.0-5.el9_0, 5.1.1-4.el9_2, 5.1.1-6.el9_4, 5.1.1-11.el8_10, 5.2.2-4.el10_0, 5.3.0-2.el10_1 06.12.2025 SB2025120604
SB20251210172
SB20251210173
and 144 more
#VU107019 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2025-22871
CWE-444 Medium
No
No
3.0.2-2.el8_4 05.04.2025 SB2025040507
SB2025040508
SB2025040739
and 109 more
#VU98022 - Use of Uninitialized Variable
CVE-2024-9355
CWE-457 Medium
No
No
5.1.1-4.el9_4, 5.1.1-9.el8_10 03.10.2024 SB2024100348
SB2024100349
SB2024101608
and 22 more
#VU97216 - Resource exhaustion
CVE-2024-34156
CWE-400 Medium
No
No
3.2.0-3.el9_0, 5.1.1-2.el9_2, 5.1.1-3.el9_4, 5.1.1-9.el9_5 12.09.2024 SB2024091261
SB2024091264
SB2024091265
and 143 more
#VU87830 - Missing release of memory after effective lifetime
CVE-2024-1394
CWE-401 Medium
No
No
5.1.1-2.el8_9, 5.1.1-2.el9_3, 5.1.1-2.el9_4 26.03.2024 SB2024032646
SB2024032647
SB2024032648
and 54 more
#VU67396 - Improper input validation
CVE-2022-27664
CWE-20 Medium
No
No
3.2.0-3.el8, 5.1.1-1.el9 15.09.2022 SB2022091520
SB2022091521
SB2022092144
and 127 more
#VU66068 - Resource exhaustion
CVE-2022-30635
CWE-400 Medium
No
No
3.2.0-2.el8, 3.2.0-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66067 - Resource exhaustion
CVE-2022-30632
CWE-400 Medium
No
No
3.2.0-2.el8, 3.2.0-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 79 more
#VU66066 - Security Features
CVE-2022-32148
CWE-254 Medium
No
No
3.2.0-2.el8, 3.2.0-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66064 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-1705
CWE-444 Medium
No
No
3.2.0-2.el8, 3.2.0-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 86 more
#VU66063 - Resource exhaustion
CVE-2022-30630
CWE-400 Medium
No
No
3.2.0-2.el8, 3.2.0-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 79 more
#VU66062 - Resource exhaustion
CVE-2022-30631
CWE-400 Medium
No
No
3.2.0-2.el8, 3.2.0-3.el9 03.08.2022 SB2022080321
SB2022080323
SB2022080324
and 100 more