CVE-2026-42127High· 7.5▾ TwilightThe public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of serv…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 11.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
grafana <= 11.6.14grafana >= 12.2.0, <= 12.2.8grafana >= 12.3.0, <= 12.3.6grafana >= 12.4.0, <= 12.4.3grafana >= 13.0.0, <= 13.0.1Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
github.com/grafana/grafana >= 2.0.0-beta1, < 11.6.15github.com/grafana/grafana >= 12.0.0, < 12.2.9github.com/grafana/grafana >= 12.3.0, < 12.3.7github.com/grafana/grafana >= 12.4.0, < 12.4.4github.com/grafana/grafana >= 13.0.0, < 13.0.2github.com/grafana/grafana < 1.9.2-0.20260616075434-82ef13993059Patched in:
github.com/grafana/grafana 1.9.2-0.20260616075434-82ef13993059Connected by shared product, vendor, weakness, or advisory.
CVE-2026-9029High· 7.3A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable
CVE-2026-10601Medium· 5.4A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints
CVE-2026-42129High· 7.7A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
CVE-2026-21728High· 7.5Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g
CVE-2026-33818High· 7.5Enforce maximum recursion depth in encoding/asn1
CVE-2026-14199High· 7.1Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected