PT-2025-38521 · WordPress+3 · Grafana-Zabbix+3

Jub0Bs

·

Published

2025-09-19

·

Updated

2025-10-29

·

CVE-2025-10630

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Grafana-Zabbix versions 5.2.1 and below
Description Grafana-Zabbix is a plugin for Grafana that visualizes monitoring data from Zabbix. Versions 5.2.1 and below contain a Regular expression Denial of Service (ReDoS) vulnerability. This issue occurs due to a user-supplied regex query, which can cause maximum CPU usage.
Recommendations Update to version 6.0.0 or later.

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10630
GHSA-G4RR-88FC-26FJ
GO-2025-3976
OPENSUSE-SU-2025:15576-1
SUSE-SU-2025:3799-1

Affected Products

Grafana
Grafana-Zabbix
Red Os
Zabbix