Skip to content
Grafana LabsCVE-2026-21723

Grafana OSS: resource exhaustion

Medium5.3CVE-2026-21723 · Published Jul 23, 2026

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana OSS
Product
>= 8.0.0, <= 11.0.0No fix yet
>= 11.0.0, <= 11.6.10No fix yet
>= 12.0.0, <= 12.0.9No fix yet
>= 12.1.0, <= 12.1.6No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana IRM: improper access control
High7.1Jul 24
Grafana Labs Loki: resource exhaustion
High7.5Jul 16
Grafana MCP Server: server-side request forgery
High8.6Jul 15
Grafana OSS: cross-site scripting
Medium6.8Jul 10
Grafana OSS: denial of service
Medium5.3Jul 10
Grafana OSS: resource exhaustion
High7.5Jul 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.