7.5

CVE-2026-8609

Pre-authentication denial of service via the OAuth login route

An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GrafanaGrafana SwEdition- Version >= 11.6.0 < 11.6.15
GrafanaGrafana SwEdition- Version >= 12.2.0 < 12.2.9
GrafanaGrafana SwEdition- Version >= 12.3.0 < 12.3.7
GrafanaGrafana SwEdition- Version >= 12.4.0 < 12.4.4
GrafanaGrafana SwEdition- Version >= 13.0.0 < 13.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.319
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security@grafana.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://grafana.com/security/security-advisories/cve-2026-8609
Vendor Advisory