CVE-2026-21723
Advisory lineage Upstream: 0 Downstream: 4
Deferred
Published: 23 Jul 2026, 01:48
Last modified:27 Aug 2026, 17:22
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
v3.1 (cve.org)
EPSS Score
0.33% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
23 Jul 2026, 01:48
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated
Description
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Trends
Current EPSS score: 0.33%• Percentile: 26%
Techniques & Countermeasures
- CWE-400•Uncontrolled Resource Consumption
The product does not properly control the allocation and maintenance of a limited resource.
Affected Systems
- grafana•grafana oss
≥ 8.0.0, ≤ 11.0.0 | ≥ 11.0.0, ≤ 11.6.10 | ≥ 12.0.0, ≤ 12.0.9 | ≥ 12.1.0, ≤ 12.1.6 | ≥ 12.2.0, ≤ 12.2.4 | ≥ 12.3.0, ≤ 12.3.2