CVE-2025-41117
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
12/02/2026
Last modified:
26/02/2026
Description
Stack traces in Grafana&#39;s Explore Traces view can be rendered as raw HTML, and thus inject malicious JavaScript in the browser. This would require malicious JavaScript to be entered into the stack trace field.<br />
<br />
Only datasources with the Jaeger HTTP API appear to be affected; Jaeger gRPC and Tempo do not appear affected whatsoever.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | 12.2.0 (including) | 12.2.4 (excluding) |
| cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | 12.3.0 (including) | 12.3.2 (excluding) |
| cpe:2.3:a:grafana:grafana:12.2.4:-:*:*:*:*:*:* | ||
| cpe:2.3:a:grafana:grafana:12.3.2:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



