Impact
An unauthenticated attacker can repeatedly invoke triggering unbounded memory growth that eventually exhausts system memory and crashes the instance. The weakness is a classic uncontrolled resource consumption scenario classified as CWE‑400 and CWE‑770, compromising availability.
Affected Systems
Grafana OSS is the affected product. The advisory does not state impacted releases, so all current Grafana OSS versions are potentially vulnerable until an official fix is issued or a workaround is applied.
Risk and Exploitability
The attack is performed over the network via the public OAuth login endpoint, which is reachable from the Internet. The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker needs no credentials to send repeated requests to drain memory and force a denial of service.
OpenCVE Enrichment