CVE-2025-41117: XSS in Grafana Explore stack trace

Published Feb 12, 2026
·
Updated

Stack traces in Grafana's Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.

Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

Affected Software

5 affected components
Grafana Grafana
Grafana Grafana>=12.2.0<12.2.4
Grafana Grafana>=12.3.0<12.3.2
Grafana Grafana=12.2.4
Grafana Grafana=12.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Grafana Jaeger HTTP datasource from your environment.

    Uninstall or disable any Jaeger HTTP API datasource in Grafana if it is not required; this eliminates the affected code path in Explore Traces.

  2. Compensating control

    Restrict access to Jaeger HTTP API datasources (network ACLs, firewall rules, or Grafana datasource permissions) and avoid using Jaeger HTTP API datasources in Explore Traces until a vendor fix is available.

Event History

Feb 12, 2026
CVE Published
via MITRE·08:49 AM
Data Sourced
via MITRE·08:49 AM
DescriptionSeverity
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-41117?

CVE-2025-41117 is considered a high-severity vulnerability due to its potential to allow cross-site scripting (XSS) attacks.

2

How do I fix CVE-2025-41117?

To mitigate CVE-2025-41117, ensure that you sanitize inputs in stack trace fields and update to the latest version of Grafana that addresses this vulnerability.

3

Which versions of Grafana are affected by CVE-2025-41117?

CVE-2025-41117 affects all versions of Grafana that allow stack traces to be rendered as raw HTML, particularly those utilizing the Jaeger HTTP API.

4

What impact does CVE-2025-41117 have on Grafana users?

The impact of CVE-2025-41117 on Grafana users includes the potential for an attacker to execute arbitrary JavaScript in the browser of users viewing affected stack traces.

5

How can I determine if my Grafana setup is vulnerable to CVE-2025-41117?

To determine if your Grafana setup is vulnerable to CVE-2025-41117, check if you are using affected versions and if your stack traces are improperly managed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203