CVE-2026-21723

Advisory lineage Upstream: 0 Downstream: 4
Deferred
Published: 23 Jul 2026, 01:48
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.33% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

23 Jul 2026, 01:48
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

CVSS Metrics

  • v3.1MEDIUMScore: 5.3CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.33% Percentile: 26%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • grafanagrafana oss

    ≥ 8.0.0, ≤ 11.0.0 | ≥ 11.0.0, ≤ 11.6.10 | ≥ 12.0.0, ≤ 12.0.9 | ≥ 12.1.0, ≤ 12.1.6 | ≥ 12.2.0, ≤ 12.2.4 | ≥ 12.3.0, ≤ 12.3.2

References (1)