Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
References
| Link | Resource |
|---|---|
| https://grafana.com/security/security-advisories/cve-2026-33382 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
13 Jul 2026, 20:51
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* | |
| References | () https://grafana.com/security/security-advisories/cve-2026-33382 - Vendor Advisory | |
| First Time |
Grafana
Grafana grafana |
10 Jul 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-10 16:16
Updated : 2026-07-13 20:51
NVD link : CVE-2026-33382
Mitre link : CVE-2026-33382
CVE.ORG link : CVE-2026-33382
JSON object : View
Products Affected
grafana
- grafana
CWE
CWE-400
Uncontrolled Resource Consumption
