CVE-2026-42127

EUVD-2026-38309
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.04%
Affected Products (NVD)
VendorProductVersion
grafanagrafana
𝑥
≤ 11.6.14
grafanagrafana
12.2.0 ≤
𝑥
≤ 12.2.8
grafanagrafana
12.3.0 ≤
𝑥
≤ 12.3.6
grafanagrafana
12.4.0 ≤
𝑥
≤ 12.4.3
grafanagrafana
13.0.0 ≤
𝑥
≤ 13.0.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
grafana
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
grafana
RHEL 8
0:9.2.10-32.el8_10.1
fixed
RHEL 9
0:10.2.6-23.el9_8.1
fixed
grafana-selinux
RHEL 8
0:9.2.10-32.el8_10.1
fixed
RHEL 9
0:10.2.6-23.el9_8.1
fixed