CVE-2026-8609

MEDIUM

Pre-authentication denial of service via the OAuth login route

Title source: cna
STIX 2.1

Description

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).

References (1)

Core 1
Core References

Scores

CVSS v3 5.3
EPSS 0.0040
EPSS Percentile 32.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (6)
grafana/grafana 11.6.0 - 11.6.15
Grafana/Grafana OSS 11.6.0 - 11.6.14
Grafana/Grafana OSS 12.2.0 - 12.2.8
Grafana/Grafana OSS 12.3.0 - 12.3.6
Grafana/Grafana OSS 12.4.0 - 12.4.3
Grafana/Grafana OSS 13.0.0 - 13.0.1
Published Jul 10, 2026
Tracked Since Jul 10, 2026