Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade grafana | Jul 13, 2026 | Jul 10, 2026 |
| Redhat_linux | — | Upgrade grafana-selinuxNo solution existsUpgrade grafana-debuginfoUpgrade grafana-debugsourceUpgrade grafana | Aug 14, 2026 | Jul 10, 2026 |
| Rocky_linux | — | Upgrade grafana-debugsourceUpgrade grafanaUpgrade grafana-selinuxUpgrade grafana-debuginfo | Aug 17, 2026 | Aug 13, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub