CVE-2026-27880 is a high-severity out-of-memory vulnerability impacting Grafana, specifically its OpenFeature feature toggle evaluation endpoint. This flaw allows an attacker to remotely trigger memory exhaustion by providing unbounded values, leading to denial-of-service for affected instances. Rated with a CVSS score of 7.5 (High), exploitation requires low attack complexity and can be performed over the network, resulting in a complete loss of availability. Although no public exploit code is currently available, the CVE is on a "Hot List" and has generated significant community discussion, indicating active monitoring and interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.1.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 12.1.10, < 12.2.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 12.2.8, < 12.3.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= 12.3.6, < 12.4.0CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* | ||
>= v12.1.0, < v12.1.10CPE match | cpe:2.3:a:grafana:grafana:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.