burnedsignal
  • Home
  • Posts
  • About
  • Archive
  • Русский
  • 中文

Grafana

How Grafana's No-Op Validator Turns Anonymous Access Into Pre-Auth SSRF

Apr 8, 2026

TL;DR Grafana OSS ships a no-op request validator for the datasource proxy endpoint. It always returns nil. Zero SSRF protection. Combined with two default …

#vulnerability-research #SSRF #grafana
burnedsignal

Exposing what was meant to stay hidden

Posts About RSS

© 2026 burnedsignal. All rights reserved.