Grafana LabsCVE-2026-21723
Grafana OSS: resource exhaustion
Medium5.3CVE-2026-21723 · Published Jul 23, 2026
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana OSS Product | >= 8.0.0, <= 11.0.0 | No fix yet |
| >= 11.0.0, <= 11.6.10 | No fix yet | |
| >= 12.0.0, <= 12.0.9 | No fix yet | |
| >= 12.1.0, <= 12.1.6 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-400
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 24 | Grafana IRM: improper access control | High7.1 | No fix yet |
| Jul 16 | Grafana Labs Loki: resource exhaustion | High7.5 | v3.7.0 |
| Jul 15 | Grafana MCP Server: server-side request forgery | High8.6 | No fix yet |
| Jul 10 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |
| Jul 10 | Grafana OSS: denial of service | Medium5.3 | No fix yet |
| Jul 10 | Grafana OSS: resource exhaustion | High7.5 | No fix yet |