The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grafana | Jun 23, 2026 | Jun 22, 2026 |
| Redhat_linux | — | Upgrade grafana-selinuxUpgrade grafana-debugsourceUpgrade grafana-debuginfoUpgrade grafana | Sep 15, 2026 | Jun 22, 2026 |
| Rocky_linux | — | Upgrade grafanaUpgrade grafana-debugsourceUpgrade grafana-selinuxUpgrade grafana-debuginfo | Sep 18, 2026 | Sep 16, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub