CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.
Configurations

No configuration.

History

27 Jan 2026, 15:15

Type Values Removed Values Added
CWE CWE-703
CWE-400

27 Jan 2026, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-27 09:15

Updated : 2026-01-27 15:15


NVD link : CVE-2026-21720

Mitre link : CVE-2026-21720

CVE.ORG link : CVE-2026-21720


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption

CWE-703

Improper Check or Handling of Exceptional Conditions