Grafana LabsCVE-2026-33382
Grafana OSS: resource exhaustion
High7.5CVE-2026-33382 · Published Jul 10, 2026 · updated Jul 13, 2026
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana OSS Product | >= 11.6.0, <= 11.6.14 | No fix yet |
| >= 12.2.0, <= 12.2.8 | No fix yet | |
| >= 12.3.0, <= 12.3.6 | No fix yet | |
| >= 12.4.0, <= 12.4.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-400
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Grafana OSS: resource exhaustion | Medium5.3 | No fix yet |
| Jul 16 | Grafana Labs Loki: resource exhaustion | High7.5 | v3.7.0 |
| Jul 15 | Grafana MCP Server: server-side request forgery | High8.6 | No fix yet |
| Jul 10 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |
| Jul 10 | Grafana OSS: denial of service | Medium5.3 | No fix yet |
| Jul 7 | Grafana: improper access control | Low3.1 | No fix yet |