LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-42127

grafana · grafana

Published
CVSS7.5
Severityhigh
WeaknessCWE-400
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-42127

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-42127.