5.3

CVE-2026-21723

CVE-2026-21723 Record

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerGrafana
Produkt Grafana OSS
Default Statusunaffected
Version <= 11.0.0
Version 8.0.0
Status affected
Version <= 11.6.10
Version 11.0.0
Status affected
Version <= 12.0.9
Version 12.0.0
Status affected
Version <= 12.1.6
Version 12.1.0
Status affected
Version <= 12.2.4
Version 12.2.0
Status affected
Version <= 12.3.2
Version 12.3.0
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.2% 0.099
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@grafana.com 5.3 1.6 3.6
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://grafana.com/security/security-advisories/cve-2026-21723