CVE-2026-21723
published 2026-07-23CVE-2026-21723: The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing…
PriorityP429medium5.3CVSS 3.1
AVNACHPRLUINSUCNINAH
EPSS
0.20%
10.0th percentile
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | — | — |
| grafana | grafana_oss | 11.0.0 – 11.6.10 | — |
| grafana | grafana_oss | 12.0.0 – 12.0.9 | — |
| grafana | grafana_oss | 12.1.0 – 12.1.6 | — |
| grafana | grafana_oss | 12.2.0 – 12.2.4 | — |
| grafana | grafana_oss | 12.3.0 – 12.3.2 | — |
| grafana | grafana_oss | 8.0.0 – 11.0.0 | — |
| multicluster-globalhub | multicluster-globalhub-grafana-rhel9 | — | — |
| rhacm2 | acm-grafana-rhel9 | — | — |
| rhceph | grafana-rhel10 | — | — |
| rhceph | grafana-rhel9 | — | — |
| rhceph | rhceph-5-dashboard-rhel8 | — | — |
| rhceph | rhceph-6-dashboard-rhel9 | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates
vendor_redhat·2026-07-23·CVSS 5.3
CVE-2026-21723 [MEDIUM] CWE-770 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates
grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
A flaw was found in Grafana. A remote attacker with very low privileges, or even anonymous access if enabled, can exploit the alertmanager templates test endpoint by mass-executing templates. This can lead to an Out-Of-Memory (OOM) error, causing the Grafana service to crash and resulting in a Denial of Service (DoS).
Statement: This Moderate flaw in Grafana allows a remote attack
GHSA
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits.
ghsa_unreviewed·2026-07-23
CVE-2026-21723 [MEDIUM] CWE-400 The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits.
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-21723 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates [fedora-all]
bugzilla·2026-07-24·CVSS 5.3
CVE-2026-21723 [MEDIUM] CVE-2026-21723 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates [fedora-all]
CVE-2026-21723 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
Bugzilla
CVE-2026-21723 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates
bugzilla·2026-07-23·CVSS 5.3
CVE-2026-21723 [MEDIUM] CVE-2026-21723 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates
CVE-2026-21723 grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates
The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.
2026-07-23
Published