Grafana · Grafana · CVE-2026-8609
**Name of the Vulnerable Software and Affected Versions**
Grafana (affected versions not specified)
**Description**
An unauthenticated attacker can trigger a denial of service by repeatedly calling the OAuth login route with unique values. This action leads to unbounded memory growth, which can exhaust the system memory and cause the instance to crash.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.