CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*

History

No history.

Information

Published : 2026-07-10 16:16

Updated : 2026-07-13 20:51


NVD link : CVE-2026-33382

Mitre link : CVE-2026-33382

CVE.ORG link : CVE-2026-33382


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-400

Uncontrolled Resource Consumption