Impact
The vulnerability allows an attacker to craft a resample query that triggers unbounded memory allocations in Grafana, causing out-of-memory crashes that deny service. The weakness maps to CWE-400 (Uncontrolled Resource Consumption), CWE-770 (Out-of-Bounds Allocation), and CWE-787 (Out-of-Bounds Write).
Affected Systems
The flaw resides in Grafana and affects any installed instance that processes resample queries. Version specifics are not provided, so all Grafana releases that support resample queries may be impacted until the fix is applied.
Risk and Exploitability
With a CVSS base score of 6.5 the flaw is of medium severity. An EPSS score of less than 1 percent and absence from the CISA KEV catalog suggest low current exploitation likelihood. The likely attack vector is inferred to be application-level via crafted query input, meaning an attacker who can submit resample queries could trigger the crash.
OpenCVE Enrichment