PT-2026-51363 · Grafana · Grafana Enterprise+1

Charlie Lewis

·

Publicado

2026-06-22

·

Atualizado

2026-06-22

·

CVE-2026-42127

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-42127

Produtos afetados

Grafana Enterprise
Grafana Oss