PT-2026-51363 · Grafana+1 · Grafana+1

·

CVE-2026-42127

·

Published

2026-06-22

·

Updated

2026-07-22

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Grafana (affected versions not specified)
Description The public dashboard query endpoint does not limit the request body size before processing. This allows unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads, which can lead to a denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this issue.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10801
BIT-GRAFANA-2026-42127
CVE-2026-42127
OPENSUSE-SU-2026:11332-1
RHSA-2026:47618
RHSA-2026:47619

Affected Products

Grafana
Red Os