CVE-2026-28376

Aliases:CGA-2gx5-jhph-f7cfCGA-3f36-cv6w-f6q6CGA-6hmr-c7xg-hpqrCGA-82wm-wg66-jpvcCGA-cvxj-2rjf-ph5fCGA-gj2x-x79h-3pg4CGA-gw8m-6v2r-93w6CGA-3jff-49px-x527CGA-3wp4-f7r4-5r3mCGA-4xmr-vqvg-cjphCGA-597r-phx8-hmpgCGA-69v9-37pj-h84xCGA-6x42-72x8-827pCGA-73p9-vx9g-ph24CGA-7hmm-v9m6-h63rCGA-93f6-6284-xpp5CGA-9j26-hqmp-vgrcCGA-c8qv-p468-63w6CGA-f9xq-fmmx-46fqCGA-fc8j-3j3g-jp9rCGA-fmc3-4cj5-77pcCGA-gjgc-q95h-hxcxCGA-h37v-24q7-v4m3CGA-h5h4-3246-gx6gCGA-hp45-qmm5-77xmCGA-jwv2-9cr6-fg24CGA-mj3h-4gcj-48hhCGA-mvw6-vhwc-w25wCGA-pw4w-rjfv-79xvCGA-px39-36hm-8gwxCGA-q24g-x6ww-6cg4CGA-qjwx-82jh-5pg4CGA-r46g-hwvr-657wCGA-r8gg-9rv6-vwhwCGA-r967-39mm-fwm5CGA-v7wf-hjv8-9h5fCGA-vh8w-344g-gqprCGA-vwp5-88gv-8ppqCGA-wg43-v5vx-q5mwCGA-wr8g-4xc2-52r7CGA-xhqg-9qf4-74vqCGA-xrmh-7r7p-hwgv
Analyzed
Published: 13 May 2026, 19:28
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.33% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2026, 19:28
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.33% Percentile: 26%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardgrafana-12.0

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.4

    < 12.4.3.02-r0

  • chainguardgrafana-fips-12.0

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.4

    < 12.4.4-r0

  • wolfigrafana-12.4

    < 12.4.3.02-r0

  • grafanagrafana

    ≥ 11.6.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 8.0.0, < 11.6.14 | ≥ 12.0.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1

  • grafanagrafana oss

    ≥ 8.0.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01

References (3)