CVE-2026-28383

Aliases:CGA-96x3-986r-2jfgCGA-c4vr-599v-7jr5CGA-h3cq-cccw-v75vCGA-h5vr-7j5m-m8qfCGA-m629-p7pp-j3rmCGA-24jh-c62w-wjr4CGA-28gj-97gh-p254CGA-2c2w-q7jh-vf7qCGA-2fh7-wq3g-753mCGA-2h37-v389-4qwwCGA-2rc9-mxh6-j6c7CGA-2w9g-jf89-9w28CGA-36vx-3r68-fhvjCGA-4cjr-cppj-3g27CGA-79gp-342f-3q3cCGA-7gjr-mvgq-cqwwCGA-8h6p-xcx7-j8q3CGA-8v3m-qv3g-f8g8CGA-8vhr-75gr-pch5CGA-92vx-74x9-whq6CGA-93fg-f2cg-qq8pCGA-97xc-g7xx-85r5CGA-99q9-cvh6-q427CGA-c5jh-5xj3-84rcCGA-f2mr-vfp6-4pvjCGA-f855-fwfm-j778CGA-fj7w-p5vc-562jCGA-gf6f-8q8h-wj87CGA-ggmf-p55x-mm7jCGA-gmph-jxmv-cp8xCGA-j7xm-m72w-7rr8CGA-jx74-j327-wrcxCGA-mrpm-q934-f46fCGA-p63x-g7r5-9r3fCGA-pjxq-45v3-g9p3CGA-q4j2-4f44-2988CGA-q8x7-8h7p-84rcCGA-rfp3-c83x-ghccCGA-vpw9-25jf-9qwhCGA-wphm-hm9h-m5hhCGA-xjwr-ccjh-9m85CGA-xpp2-87gx-f8vh
Analyzed
Published: 13 May 2026, 19:28
Last modified:27 Aug 2026, 17:22

Vulnerability Summary

Overall Risk (default)
medium
26/100
CVSS Score
6.5 MEDIUM
v3.1 (cve.org)
EPSS Score
0.33% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 May 2026, 19:28
Published
Vulnerability first disclosed
27 Aug 2026, 17:22
Last Modified
Vulnerability information updated

Description

A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request body into memory. An authenticated user can exploit this to trigger an out-of-memory condition, potentially causing a denial of service.

CVSS Metrics

  • v3.1MEDIUMScore: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.33% Percentile: 26%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • chainguardgrafana-12.0

    all

  • chainguardgrafana-12.1

    all

  • chainguardgrafana-12.4

    < 12.4.3.02-r0

  • chainguardgrafana-fips-12.0

    all

  • chainguardgrafana-fips-12.1

    all

  • chainguardgrafana-fips-12.4

    < 12.4.4-r0

  • wolfigrafana-12.4

    < 12.4.3.02-r0

  • grafanagrafana

    ≥ 8.5.0, < 11.6.14 | ≥ 12.2.0, < 12.2.8 | ≥ 12.3.0, < 12.3.6 | ≥ 12.4.0, < 12.4.3 | 11.6.14 | 11.6.14:security01 | 12.2.8 | 12.2.8:security01 | 12.3.6 | 12.3.6:security01 | 12.4.3 | 13.0.0 | 13.0.1

  • grafanagrafana oss

    ≥ 6.7.0, ≤ 11.6.14 | ≥ 11.6.14, < 11.6.14+security-04 | ≥ 12.0.0, ≤ 12.2.8 | ≥ 12.2.8, < 12.2.8+security-04 | ≥ 12.3.0, ≤ 12.3.6 | ≥ 12.3.6, < 12.3.6+security-04 | ≥ 12.4.0, ≤ 12.4.3 | ≥ 12.4.3, < 12.4.3+security-02 | ≥ 13.0.0, ≤ 13.0.1 | ≥ 13.0.1, < 13.0.1+security-01

References (3)