Input validation error in Grafana - CVE-2026-33378
Published: May 18, 2026
Grafana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the $__timeGroup macro when processing user-supplied negative interval values in a SQL datasource query. A remote user can supply a specially crafted query parameter to cause a denial of service.
Exploitation requires the use of a SQL datasource.