ReDoS Vulnerability in Grafana-Zabbix Plugin by Grafana
CVE-2025-10630
4.3MEDIUM
What is CVE-2025-10630?
The Grafana-Zabbix plugin for Grafana suffers from a Regular Expression Denial of Service (ReDoS) vulnerability in versions 5.2.1 and earlier. This flaw arises from how user-supplied regex queries are processed, leading to excessive CPU usage that could impact system performance. Users are strongly advised to upgrade to version 6.0.0 or later to mitigate this issue and enhance system stability.
Affected Version(s)
grafana-zabbix-plugin 0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
jub0bs