Impact
An unauthenticated attacker can repeatedly invoke the OAuth login route with unique values, causing unbounded memory growth that eventually exhausts system memory and crashes the instance. This behaviour is classified as CWE‑400 and CWE‑770, which compromise availability. The description is taken directly from the advisory information.
Affected Systems
Based on the advisory, Grafana OSS is the affected product. The advisory does not list specific releases, so it is inferred that all current Grafana OSS versions may be vulnerable until an official fix is issued or a workaround is applied.
Risk and Exploitability
Based on the description, it is inferred that the attacker targets the publicly exposed OAuth login endpoint over the network, sending repeated requests to drain memory and force a denial of service. The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker requires no credentials to perform this exploit.
OpenCVE Enrichment