Race condition in Grafana - CVE-2026-28379
Published: May 18, 2026
Grafana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to a race condition in Grafana Live when handling concurrent requests. A remote user can send concurrent requests to cause a denial of service.
The issue can trigger a fatal map access error and complete service unavailability until the Grafana server is restarted.