CVE-2026-8609
MEDIUMPre-authentication denial of service via the OAuth login route
Title source: cnaDescription
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
References (1)
Core 1
Core References
Vendor Advisory vendor-advisory
https://grafana.com/security/security-advisories/cve-2026-8609
Scores
CVSS v3
5.3
EPSS
0.0040
EPSS Percentile
32.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (6)
grafana/grafana
11.6.0 - 11.6.15
Grafana/Grafana OSS
11.6.0 - 11.6.14
Grafana/Grafana OSS
12.2.0 - 12.2.8
Grafana/Grafana OSS
12.3.0 - 12.3.6
Grafana/Grafana OSS
12.4.0 - 12.4.3
Grafana/Grafana OSS
13.0.0 - 13.0.1
Published
Jul 10, 2026
Tracked Since
Jul 10, 2026