PT-2026-51363 · Grafana · Grafana Enterprise+1

Charlie Lewis

·

Published

2026-06-22

·

Updated

2026-06-22

·

CVE-2026-42127

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-42127

Affected Products

Grafana Enterprise
Grafana Oss