CVE-2026-33382
published 2026-07-10CVE-2026-33382: Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.39%
32.1th percentile
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | — | — |
| grafana | grafana | >= 11.6.0 < 11.6.15 | 11.6.15 |
| grafana | grafana | >= 12.2.0 < 12.2.9 | 12.2.9 |
| grafana | grafana | >= 12.3.0 < 12.3.7 | 12.3.7 |
| grafana | grafana | >= 12.4.0 < 12.4.4 | 12.4.4 |
| grafana | grafana | >= 13.0.0 < 13.0.2 | 13.0.2 |
| grafana | grafana_oss | 11.6.0 – 11.6.14 | — |
| grafana | grafana_oss | 12.2.0 – 12.2.8 | — |
| grafana | grafana_oss | 12.3.0 – 12.3.6 | — |
| grafana | grafana_oss | 12.4.0 – 12.4.3 | — |
| grafana | grafana_oss | 13.0.0 – 13.0.1 | — |
| rhceph | grafana-rhel10 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads
vendor_redhat·2026-07-10·CVSS 7.5
CVE-2026-33382 [HIGH] CWE-770 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads
grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
A flaw in Grafana's API endpoints allows remote attackers to send excessively large request bodies without authentication. This exhausts server memory, resulting in a complete denial of service (DoS).
Statement: Moderate: This denial of service vulnerability in Grafana stems from a lack of request body size limits on certain API endpoints, some of which are unauthenticated. Exploitation by a remote attacker sending large pay
GHSA
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it.
ghsa_unreviewed·2026-07-10
CVE-2026-33382 [HIGH] CWE-400 Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it.
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-33382 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads [fedora-all]
bugzilla·2026-07-16·CVSS 7.5
CVE-2026-33382 [HIGH] CVE-2026-33382 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads [fedora-all]
CVE-2026-33382 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
Bugzilla
CVE-2026-33382 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads
bugzilla·2026-07-10·CVSS 7.5
CVE-2026-33382 [HIGH] CVE-2026-33382 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads
CVE-2026-33382 grafana: Grafana: Denial of Service via excessive memory allocation from large API request payloads
Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.
2026-07-10
Published