CVE-2026-21720Disclosure(grafana / grafana)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-703CWE-772

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-01-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
grafana

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-29: 1Mentions · 2026-04-07: 1Technical Details · 2026-04-07: 101-2904-07
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Grafana ❗ CVE-2026-21721 ❗ CVE-2026-21720 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-grafana/ https://t.co/1H4Qhzv7aQ

    Post summary

    The tweet merely announces the presence of CVE‑2026‑21721 and CVE‑2026‑21720 for Grafana without providing technical details, patches, or exploitation information.

    00001128
    6.6K followersView on X
  • Red Hornet Intel@RedHornet_Intel
    Disclosure

    CVE-2026-21720 In Grafana Enterprise, unauth /avatar/:hash requests spawn goroutines that leak on timeout due to unbuffered channel, resulting in memory exhaustion and DoS. Severity: High PoC: n/a Exploited: n/a Product: grafana:grafana-grafana-enterprise

    Post summary

    The post announces CVE‑2026‑21720 as a high‑severity DoS vulnerability in Grafana Enterprise caused by goroutine leaks on unauthenticated /avatar requests. No PoC, exploit, or patch is reported, and no evidence of active exploitation is provided.

    0000014
    1 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana---
Appgrafanagrafana12.3.0--
Appgrafanagrafana12.3.0--

Explore more