#VU124707 Resource exhaustion in Grafana - CVE-2026-27880
Published: March 31, 2026
Grafana
Grafana Labs
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in the OpenFeature feature toggle evaluation endpoint when processing unbounded input data. A remote attacker can send a specially crafted request with large input values to cause a denial of service.
The issue can lead to out-of-memory crashes.