Goroutine Exhaustion in Grafana by Image Refresh Mechanism
CVE-2026-21720
Key Information:
- Vendor
Grafana
- Vendor
- CVE Published:
- 27 January 2026
What is CVE-2026-21720?
Grafana contains a vulnerability that allows for excessive goroutine creation during image refresh requests. When a user requests a Gravatar image, an uncached request triggers the spawning of a goroutine to refresh the image. However, if the request takes longer than three seconds, the handler times out, resulting in the goroutine being unable to complete its task. This leads to an increase in active goroutines, which consumes memory over time. If the system experiences sustained traffic with various hash requests, it may lead to a memory exhaust scenario, causing Grafana to crash. This vulnerability highlights the importance of monitoring and optimizing server performance under load.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
grafana/grafana 3.0.0 < 11.6.9
grafana/grafana 3.0.0 < 12.0.8
grafana/grafana 3.0.0 < 12.1.5
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved