Impact
The vulnerability lies in multiple Grafana Open Source API endpoints that fail to impose a limit on the size of the request body before processing. An attacker who can send arbitrarily large payloads forces Grafana to allocate excessive amounts of memory, which in turn can exhaust the server’s memory resources and bring the service to a halt. The result is a denial of service in which legitimate users lose access to the Grafana interface until the process recovers or is restarted.
Affected Systems
All deployed Grafana Open Source installations that expose the affected endpoints are vulnerable. Because the advisory does not enumerate specific revision numbers, any instance of Grafana OSS that has not applied the latest fixes should be assumed at risk.
Risk and Exploitability
The CVSS base score of 7.5 categorises this flaw as high severity. The description indicates that the attack can be launched through standard HTTP requests and that some endpoints lack authentication, implying that remote attackers can exploit the vulnerability with minimal effort. The EPSS score of < 1% reflects a very low probability of existing exploitation in the wild, and the issue is not present in the CISA KEV catalog. Nonetheless, the combination of a high severity rating and a low barrier to exploitation makes it a priority for maintaining service availability.
OpenCVE Enrichment