Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grafana | Jul 13, 2026 | Jul 10, 2026 |
| Redhat_linux | — | Upgrade grafanaUpgrade grafana-debugsourceNo solution existsUpgrade grafana-selinuxUpgrade grafana-debuginfo | Aug 14, 2026 | Jul 10, 2026 |
| Rocky_linux | — | Upgrade grafanaUpgrade grafana-debugsourceUpgrade grafana-debuginfoUpgrade grafana-selinux | Aug 17, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub