Impact
The flaw is a race condition in Grafana Live that permits a logged‑in user with the Viewer role to dispatch concurrent requests that trigger a fatal map access error, crashing the Grafana server and rendering all services unavailable until a restart. The immediate consequence is a denial of service for every user of the affected instance.
Affected Systems
Grafana OSS installations are impacted. No specific version ranges are provided in the advisory, so any deployment of Grafana OSS should be considered potentially vulnerable unless a patch has been applied.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of < 1% denotes a very low probability of exploitation in the wild, although the vulnerability is not listed in KEV. Attack requires authentic access with a Viewer role; an attacker can send burst concurrent Live requests to trigger a crash, causing a service outage. No public exploit is known, but lack of KEV status does not reduce risk inside trusted environments.
OpenCVE Enrichment