Skip to content
Grafana LabsCVE-2026-33382

Grafana OSS: resource exhaustion

High7.5CVE-2026-33382 · Published Jul 10, 2026 · updated Jul 13, 2026

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana OSS
Product
>= 11.6.0, <= 11.6.14No fix yet
>= 12.2.0, <= 12.2.8No fix yet
>= 12.3.0, <= 12.3.6No fix yet
>= 12.4.0, <= 12.4.3No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana OSS: resource exhaustion
Medium5.3Jul 23
Grafana Labs Loki: resource exhaustion
High7.5Jul 16
Grafana MCP Server: server-side request forgery
High8.6Jul 15
Grafana OSS: cross-site scripting
Medium6.8Jul 10
Grafana OSS: denial of service
Medium5.3Jul 10
Grafana: improper access control
Low3.1Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.