CVE-2026-8609
published 2026-07-10CVE-2026-8609: An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.40%
33.1th percentile
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| grafana | grafana | — | — |
| grafana | grafana | >= 11.6.0 < 11.6.15 | 11.6.15 |
| grafana | grafana | >= 12.2.0 < 12.2.9 | 12.2.9 |
| grafana | grafana | >= 12.3.0 < 12.3.7 | 12.3.7 |
| grafana | grafana | >= 12.4.0 < 12.4.4 | 12.4.4 |
| grafana | grafana | >= 13.0.0 < 13.0.2 | 13.0.2 |
| grafana | grafana_oss | 11.6.0 – 11.6.14 | — |
| grafana | grafana_oss | 12.2.0 – 12.2.8 | — |
| grafana | grafana_oss | 12.3.0 – 12.3.6 | — |
| grafana | grafana_oss | 12.4.0 – 12.4.3 | — |
| grafana | grafana_oss | 13.0.0 – 13.0.1 | — |
| rhceph | grafana-rhel10 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denia
ghsa_unreviewed·2026-07-10
CVE-2026-8609 [MEDIUM] CWE-400 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denia
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
Red Hat
grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route
vendor_redhat·2026-07-10·CVSS 7.5
CVE-2026-8609 [HIGH] CWE-770 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route
grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
A flaw was found in Grafana. An unauthenticated attacker can repeatedly access the OAuth login route with unique values. This can lead to unbounded memory growth, eventually exhausting system memory and causing the Grafana instance to crash. This results in a denial of service for legitimate users.
Statement: The flaw in Grafana is rated Moderate, as an unauthenticated attacker can trigger a denial of service by repeatedly accessing the OAuth login route, leading to unbounded memory growth an
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-8609 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route [fedora-all]
bugzilla·2026-07-16·CVSS 7.5
CVE-2026-8609 [HIGH] CVE-2026-8609 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route [fedora-all]
CVE-2026-8609 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
Bugzilla
CVE-2026-8609 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route
bugzilla·2026-07-10·CVSS 7.5
CVE-2026-8609 [HIGH] CVE-2026-8609 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route
CVE-2026-8609 grafana: Grafana: Denial of Service via unbounded memory growth in OAuth login route
An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash the Grafana instance (denial of service).
2026-07-10
Published