Skip to content
Grafana LabsCVE-2026-21729

Grafana Labs Loki: resource exhaustion

High7.5CVE-2026-21729 · Published Jul 16, 2026

Loki queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Loki
Product
>= v3.0.0, < v3.7.0v3.7.0
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-770

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana IRM: improper access control
High7.1Jul 24
Grafana OSS: resource exhaustion
Medium5.3Jul 23
Grafana MCP Server: server-side request forgery
High8.6Jul 15
Grafana OSS: cross-site scripting
Medium6.8Jul 10
Grafana OSS: denial of service
Medium5.3Jul 10
Grafana OSS: resource exhaustion
High7.5Jul 10

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.