<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Grafana Labs</title><description>Actively exploited vulnerabilities affecting Grafana Labs products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/grafana-labs.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2021-43798 — Grafana Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2021-43798</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2021-43798</guid><description>Grafana, a widely deployed open-source analytics and monitoring platform, contains a path traversal flaw that lets an unauthenticated attacker request URLs crafted to escape the web root and read arbitrary local files on the server. This means sensitive files — including configuration files potentially containing credentials or secrets — could be exposed without any login required, making this a high-priority risk for any organization running a vulnerable Grafana instance.</description><pubDate>Thu, 09 Oct 2025 00:00:00 GMT</pubDate><category>Grafana Labs</category><category>Grafana</category></item></channel></rss>