CVE 6.5 MEDIUM

Grafana Live push endpoint allows unbounded memory allocation leading to OOM_CVE-2026-28376

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

Basic Information

ID CVE-2026-28376
Source GRAFANA
Published May 13, 2026 at 19:28
Modified May 13, 2026 at 19:35

Affected Product

Vendor Grafana
Product Grafana OSS
Version 8.0.0
Affected Versions Grafana Grafana OSS 8.0.0
Grafana Grafana OSS 11.6.14
Grafana Grafana OSS 12.0.0
Grafana Grafana OSS 12.2.8
Grafana Grafana OSS 12.3.0
Grafana Grafana OSS 12.3.6
Grafana Grafana OSS 12.4.0
Grafana Grafana OSS 12.4.3
Grafana Grafana OSS 13.0.0
Grafana Grafana OSS 13.0.1

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.