Grafana HTML Injection Vulnerability in Jaeger HTTP API Datasources

Vulnerability

A vulnerability exists in Grafana's Explore Traces view, where stack traces can be rendered as raw HTML. This flaw allows for the injection of malicious JavaScript into the browser. The issue arises only when harmful JavaScript is entered into the stack trace field. Currently, this vulnerability affects Grafana when using datasources that connect to the Jaeger HTTP API; those using Jaeger gRPC or Tempo do not experience this issue.

Impact

Exploitation of this vulnerability could lead to cross-site scripting (XSS) attacks, allowing injected JavaScript to be executed in the context of the user's browser.

Added: Feb 12, 2026, 10:18 AM
Updated: Feb 12, 2026, 3:59 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
1.7
exploitability
4.6
remediation
8.3
relevance
2.9
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.