Allocation of Resources Without Limits or Throttling in Grafana - CVE-2026-28383
Published: May 18, 2026
Grafana
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to uncontrolled memory allocation in the plugin resources endpoint when handling requests with large request bodies. A remote user can send a specially crafted request to cause a denial of service.
The issue can trigger an out-of-memory condition.