StackRadar

CVE-2026-42129

High

Advisory

Published 22 Jun 2026In the index since 22 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.004
38th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
19
of 17,828 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability.

Carried by container images the latest versions of 19 of 17,828 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
github.com/grafana/grafanagolangv0.0.0-20230830192226-0cfa76b22dd5, v0.0.0-20231011162216-849c612fcb73, v0.0.0-20231218140301-1e84fede543a, v0.0.0-20250812085420-df5de8219b41+dirty+10 more1.9.2-0.20260616075434-82ef1399305916
OSV records
GHSA-f74p-cwhp-x2wx

Charts affected

19 by stars
ChartLatestAffected imagesRadar Score
deepflowdeepflow6.2.2011 of 8See more

deepflow deepflow 6.2.201

1 of the 8 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:9.3.6e5a9655dabef
github.com/grafana/grafana@v9.3.6
no fix listed

Open the chart page →

16,073
kubecostmesosphere-stable0.37.51 of 9See more

kubecost mesosphere-stable 0.37.5

1 of the 9 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:9.4.71a359d92f40e
github.com/grafana/grafana@v9.4.7
no fix listed

Open the chart page →

17,975
sn-platformstreamnative1.11.451 of 9See more

sn-platform streamnative 1.11.45

1 of the 9 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/grafana/grafana@v9.5.6
no fix listed

Open the chart page →

69,821
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:9.4.376dcf36e7d2a
github.com/grafana/grafana@v9.4.3
no fix listed

Open the chart page →

18,049
dbrepodbrepo1.13.31 of 25See more

dbrepo dbrepo 1.13.3

1 of the 25 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/grafana/grafana@v11.3.1
no fix listed

Open the chart page →

53,884
carettagroundcover0.0.161 of 3See more

caretta groundcover 0.0.16

1 of the 3 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/grafana/grafana@v9.3.1
no fix listed

Open the chart page →

6,865
drogue-cloud-examplesdrogue-iotVerified publisher0.7.111 of 6See more

drogue-cloud-examples drogue-iot 0.7.11

1 of the 6 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
github.com/grafana/grafana@v9.2.4
no fix listed

Open the chart page →

31,020
drogue-cloud-metricsdrogue-iotVerified publisher0.7.111 of 8See more

drogue-cloud-metrics drogue-iot 0.7.11

1 of the 8 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:9.2.4057896e23443
github.com/grafana/grafana@v9.2.4
no fix listed

Open the chart page →

13,636
upgrade-responderepinioVerified publisher0.2.01 of 5See more

upgrade-responder epinio 0.2.0

1 of the 5 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:10.1.50679e877ba20
github.com/grafana/grafana@v0.0.0-20231011162216-849c612fcb73
1.9.2-0.20260616075434-82ef13993059

Open the chart page →

7,469
pyroscope-monitoringgrafana0.1.11 of 6See more

pyroscope-monitoring grafana 0.1.1

1 of the 6 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
1.9.2-0.20260616075434-82ef13993059

Open the chart page →

8,531
routergroundcover1.12.3781 of 7See more

router groundcover 1.12.378

1 of the 7 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
github.com/grafana/grafana@v11.3.7
no fix listed

Open the chart page →

6,256
grafanakubeblocksVerified publisher6.59.41 of 1See more

grafana kubeblocks 6.59.4

1 of the 1 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/grafana/grafana@v0.0.0-20230830192226-0cfa76b22dd5
1.9.2-0.20260616075434-82ef13993059

Open the chart page →

3,620
deepflowkubesphere-stable6.2.6061 of 8See more

deepflow kubesphere-stable 6.2.606

1 of the 8 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:9.5.239c849cebccc
github.com/grafana/grafana@v9.5.2
no fix listed

Open the chart page →

18,588
grafananodepulse7.1.01 of 1See more

grafana nodepulse 7.1.0

1 of the 1 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:10.2.36b5b37eb35bb
github.com/grafana/grafana@v0.0.0-20231218140301-1e84fede543a
1.9.2-0.20260616075434-82ef13993059

Open the chart page →

3,025
lensoci-ai-incubations0.1.141 of 16See more

lens oci-ai-incubations 0.1.14

1 of the 16 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
grafana/grafana:12.1.1a1701c218024
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
1.9.2-0.20260616075434-82ef13993059

Open the chart page →

17,317
archive-analysispcp-helm-chartsVerified publisher1.0.11 of 1See more

archive-analysis pcp-helm-charts 1.0.1

1 of the 1 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
ghcr.io/performancecopilot/archive-analysis:latestba9f5a44ad68
github.com/grafana/grafana@v10.2.6
no fix listed

Open the chart page →

1,386
npre-essentialsphntom0.1.601 of 22See more

npre-essentials phntom 0.1.60

1 of the 22 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/grafana/grafana@v9.3.1
no fix listed

Open the chart page →

26,954
sn-platform-slimstreamnative1.11.451 of 6See more

sn-platform-slim streamnative 1.11.45

1 of the 6 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/grafana/grafana@v9.5.6
no fix listed

Open the chart page →

64,468
grafanasvtech-public-helm-charts1.0.01 of 2See more

grafana svtech-public-helm-charts 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-42129.

Container imageDigestPackageFixed in
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/grafana/grafana@v9.5.6
no fix listed

Open the chart page →

11,140

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
grafana/grafana:9.2.4057896e23443
github.com/grafana/grafana@v9.2.4
no fix listed
2
streamnative/apache-pulsar-grafana-dashboard-k8s:0.1.20e6d7aa3ef32
github.com/grafana/grafana@v9.5.6
no fix listed
2
quay.io/groundcover/grafana:9.3.18c65b333a3d3
github.com/grafana/grafana@v9.3.1
no fix listed
2
bitnamilegacy/grafana:11.4.0-debian-12-r0cb8ab5515676
github.com/grafana/grafana@v11.3.1
no fix listed
1
grafana/grafana:10.1.50679e877ba20
github.com/grafana/grafana@v0.0.0-20231011162216-849c612fcb73
1.9.2-0.20260616075434-82ef13993059
1
grafana/grafana:9.4.71a359d92f40e
github.com/grafana/grafana@v9.4.7
no fix listed
1
grafana/grafana:10.1.11b9ca4bbc4a2
github.com/grafana/grafana@v0.0.0-20230830192226-0cfa76b22dd5
1.9.2-0.20260616075434-82ef13993059
1
grafana/grafana:9.5.239c849cebccc
github.com/grafana/grafana@v9.5.2
no fix listed
1
grafana/grafana:10.2.36b5b37eb35bb
github.com/grafana/grafana@v0.0.0-20231218140301-1e84fede543a
1.9.2-0.20260616075434-82ef13993059
1
grafana/grafana:9.4.376dcf36e7d2a
github.com/grafana/grafana@v9.4.3
no fix listed
1
grafana/grafana:12.1.1a1701c218024
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
1.9.2-0.20260616075434-82ef13993059
1
grafana/grafana:9.3.6e5a9655dabef
github.com/grafana/grafana@v9.3.6
no fix listed
1
grafana/otel-lgtm:0.11.1009d8c3ce4f3a
github.com/grafana/grafana@v0.0.0-20250812085420-df5de8219b41+dirty
1.9.2-0.20260616075434-82ef13993059
1
svtechnmaa/svtech_grafana:v1.2.21d71314424aa
github.com/grafana/grafana@v9.5.6
no fix listed
1
ghcr.io/performancecopilot/archive-analysis:latestba9f5a44ad68
github.com/grafana/grafana@v10.2.6
no fix listed
1
public.ecr.aws/groundcovercom/grafana-groundcover:v0.0.54-grafana11.3.7ee9d973e3952
github.com/grafana/grafana@v11.3.7
no fix listed
1

syft 1.42.1 · advisories as of 22 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.