Grafana LabsCVE-2026-8609
Grafana OSS: denial of service
Medium5.3CVE-2026-8609 · Published Jul 10, 2026 · updated Jul 13, 2026
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Grafana OSS Product | >= 11.6.0, <= 11.6.14 | No fix yet |
| >= 12.2.0, <= 12.2.8 | No fix yet | |
| >= 12.3.0, <= 12.3.6 | No fix yet | |
| >= 12.4.0, <= 12.4.3 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-400
More Grafana Labs advisories
All Grafana Labs| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 23 | Grafana OSS: resource exhaustion | Medium5.3 | No fix yet |
| Jul 16 | Grafana Labs Loki: resource exhaustion | High7.5 | v3.7.0 |
| Jul 15 | Grafana MCP Server: server-side request forgery | High8.6 | No fix yet |
| Jul 10 | Grafana OSS: cross-site scripting | Medium6.8 | No fix yet |
| Jul 10 | Grafana OSS: resource exhaustion | High7.5 | No fix yet |
| Jul 7 | Grafana: improper access control | Low3.1 | No fix yet |