12.4.0
2026-03-04T21:03:05Z•0053495ccbb5c51726f7ddd5ce17e9842f36c02a4fa3c308d53aa7800916892d
apiauthorizationdos-mitigationgografanainput-sanitizationnanogitrbacreleasesecuritysupply-chainxss
What happened
Grafana releases (notably 12.4.0 and several 12.x/11.x patch releases) include multiple security-related fixes and hardening: an API fix adding a missing scope check on dashboards (PR #116885) addressing an authorization gap; HTML sanitization in TraceView to mitigate XSS (PR #117866); changes to public dashboards annotations/timerange behavior (reducing unintended time-range exposure); limits on expanded notification templates to reduce potential resource exhaustion; addition of RBAC for alerting enrichments (Enterprise); and supply-chain/stability updates such as a nanogit bump and Go update
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- grafana_grafana_releases
- Record identifier
- 0053495ccbb5c51726f7ddd5ce17e9842f36c02a4fa3c308d53aa7800916892d
- Enrichment time
- 2026-03-04T21:03:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.