Impact
The vulnerable endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) allows the execution of arbitrary templates without any memory restrictions. When an attacker submits a large or complex set of templates, Grafana can run out of memory, triggering a crash that disables the service and its dashboards.
Affected Systems
All Grafana Open Source Edition deployments that expose the Alertmanager template test endpoint are susceptible. The advisory does not list specific version ranges, so any version that has not applied the latest fix may be affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of current exploitation. Grafana is not in the CISA KEV catalog. The likely attack vector is remote HTTP, inferred from the description that the vulnerable endpoint is accessed over HTTP; the endpoint requires only low privileges and even anonymous access, making exploitation trivial for an attacker using crafted template payloads to cause a crash.
OpenCVE Enrichment