CVE-2026-42127
HIGHGrafana pre-auth DoS through arbitrarily large input to public dashboard query handler
Title source: cnaDescription
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://grafana.com/security/security-advisories/cve-2026-42127
Scores
CVSS v3
7.5
EPSS
0.0043
EPSS Percentile
35.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
CWE-770
Status
published
Products (16)
grafana/grafana
< 11.6.14
Grafana/Grafana Enterprise
< 11.6.14
Grafana/Grafana Enterprise
< 12.2.8
Grafana/Grafana Enterprise
< 12.3.6
Grafana/Grafana Enterprise
< 12.4.3
Grafana/Grafana Enterprise
< 13.0.1
Grafana/Grafana Enterprise
11.6.0 - 11.6.14
Grafana/Grafana Enterprise
12.2.0 - 12.2.8
Grafana/Grafana Enterprise
12.3.0 - 12.3.6
Grafana/Grafana Enterprise
12.4.0 - 12.4.3
... and 6 more
Published
Jun 22, 2026
Tracked Since
Jun 22, 2026