Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.6.0, < 11.6.15CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* | ||
>= 12.2.0, < 12.2.9CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* | ||
>= 12.3.0, < 12.3.7CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* | ||
>= 12.4.0, < 12.4.4CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* | ||
>= 13.0.0, < 13.0.2CPE matchmatch criteria | cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.