CVE-2026-33382

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*

History

13 Jul 2026, 20:51

Type Values Removed Values Added
CPE cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
References () https://grafana.com/security/security-advisories/cve-2026-33382 - () https://grafana.com/security/security-advisories/cve-2026-33382 - Vendor Advisory
First Time Grafana
Grafana grafana

10 Jul 2026, 16:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-10 16:16

Updated : 2026-07-13 20:51


NVD link : CVE-2026-33382

Mitre link : CVE-2026-33382

CVE.ORG link : CVE-2026-33382


JSON object : View

Products Affected

grafana

  • grafana
CWE
CWE-400

Uncontrolled Resource Consumption