CVE-2026-28376Disclosure(grafana / grafana)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch grafana grafana systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • grafana

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
grafana

6 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-13: 1Technical Details · 2026-05-14: 105-1305-14
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 Moderate - Grafana Live Push Endpoint Denial of Service (CVE-2026-28376) Grafana contains a vulnerability in the Live push endpoint where large or streaming request bodies can trigger unbounded memory allocation, potentially leading to out-of-memory conditions and service disruption. The issue can be exploited by an authenticated user with access to the Grafana Live API. 👉 Monitor vendor advisories and apply security updates once fixes become available

    Post summary

    The tweet announces a moderate denial‑of‑service CVE in Grafana’s Live Push endpoint, highlighting unbounded memory allocation issues and urging users to monitor advisories and apply forthcoming patches.

    0002098
    255 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28376 The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memor… https://www.cve.org/CVERecord?id=CVE-2026-28376

    Post summary

    The post announces a Grafana Live push endpoint vulnerability that can cause unbounded memory allocation and possible denial‑of‑service. No proof‑of‑concept, exploit code, patch, or active exploitation is mentioned.

    00000168
    57.5K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
Appgrafanagrafana---
Appgrafanagrafana11.6.14--
Appgrafanagrafana11.6.14--
Appgrafanagrafana12.2.8--
Appgrafanagrafana12.2.8--
Appgrafanagrafana12.3.6--
Appgrafanagrafana12.3.6--
Appgrafanagrafana12.4.3--
Appgrafanagrafana13.0.0--
Appgrafanagrafana13.0.1--

Explore more