CVE-2026-33382

HIGH

Grafana OSS - Denial of Service via Unbounded Request Body Size

Title source: rule
STIX 2.1

Description

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0039
EPSS Percentile 31.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (6)
grafana/grafana 11.6.0 - 11.6.15
Grafana/Grafana OSS 11.6.0 - 11.6.14
Grafana/Grafana OSS 12.2.0 - 12.2.8
Grafana/Grafana OSS 12.3.0 - 12.3.6
Grafana/Grafana OSS 12.4.0 - 12.4.3
Grafana/Grafana OSS 13.0.0 - 13.0.1
Published Jul 10, 2026
Tracked Since Jul 10, 2026