Goroutine Exhaustion in Grafana by Image Refresh Mechanism
CVE-2026-21720

7.5HIGH

Key Information:

Vendor

Grafana

Vendor
CVE Published:
27 January 2026

What is CVE-2026-21720?

Grafana contains a vulnerability that allows for excessive goroutine creation during image refresh requests. When a user requests a Gravatar image, an uncached request triggers the spawning of a goroutine to refresh the image. However, if the request takes longer than three seconds, the handler times out, resulting in the goroutine being unable to complete its task. This leads to an increase in active goroutines, which consumes memory over time. If the system experiences sustained traffic with various hash requests, it may lead to a memory exhaust scenario, causing Grafana to crash. This vulnerability highlights the importance of monitoring and optimizing server performance under load.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

grafana/grafana 3.0.0 < 11.6.9

grafana/grafana 3.0.0 < 12.0.8

grafana/grafana 3.0.0 < 12.1.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.