CVE-2025-41117

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/02/2026
Last modified:
12/02/2026

Description

Stack traces in Grafana&amp;#39;s Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.<br /> <br /> Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.

References to Advisories, Solutions, and Tools