5.3
CVE-2026-21723
- EPSS 0.2%
- Veröffentlicht 23.07.2026 01:48:16
- Zuletzt bearbeitet 23.07.2026 17:55:03
- CVE-Watchlists
- Unerledigt
CVE-2026-21723 Record
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGrafana
≫
Produkt
Grafana OSS
Default Statusunaffected
Version <=
11.0.0
Version
8.0.0
Status
affected
Version <=
11.6.10
Version
11.0.0
Status
affected
Version <=
12.0.9
Version
12.0.0
Status
affected
Version <=
12.1.6
Version
12.1.0
Status
affected
Version <=
12.2.4
Version
12.2.0
Status
affected
Version <=
12.3.2
Version
12.3.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.099 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@grafana.com | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-400 Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
https://grafana.com/security/security-advisories/cve-2026-21723