Skip to content
Grafana LabsCVE-2026-8609

Grafana OSS: denial of service

Medium5.3CVE-2026-8609 · Published Jul 10, 2026 · updated Jul 13, 2026

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

Grafana Labs advisory

Affected versions

PackageAffectedFixed in
Grafana OSS
Product
>= 11.6.0, <= 11.6.14No fix yet
>= 12.2.0, <= 12.2.8No fix yet
>= 12.3.0, <= 12.3.6No fix yet
>= 12.4.0, <= 12.4.3No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-400

More Grafana Labs advisories

All Grafana Labs
Advisory
Grafana OSS: resource exhaustion
Medium5.3Jul 23
Grafana Labs Loki: resource exhaustion
High7.5Jul 16
Grafana MCP Server: server-side request forgery
High8.6Jul 15
Grafana OSS: cross-site scripting
Medium6.8Jul 10
Grafana OSS: resource exhaustion
High7.5Jul 10
Grafana: improper access control
Low3.1Jul 7

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.