Security Advisory

CVE-2026-33376

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-13 19:28:34
Last updated 2026-07-24 12:23:21
Assigner GRAFANA
CVSS score 7.4
State PUBLISHED

Description

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.