Memory Exhaustion Vulnerability in Grafana
CVE-2026-21723

5.3MEDIUM

Key Information:

Vendor

Grafana

Vendor
CVE Published:
23 July 2026

What is CVE-2026-21723?

The Grafana alertmanager templates test endpoint allows for template execution without imposing memory limits, leading to potential denial-of-service conditions. When exploited, an attacker can initiate the execution of multiple templates in quick succession, resulting in out-of-memory (OOM) errors that crash the Grafana service. This vulnerability poses a risk especially when anonymous access is enabled, as it requires minimal privileges to exploit. It is crucial for users to remain vigilant and update to the latest version to mitigate these risks.

Affected Version(s)

Grafana OSS 8.0.0 <= 11.0.0

Grafana OSS 11.0.0 <= 11.6.10

Grafana OSS 12.0.0 <= 12.0.9

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nacl (Researcher)
.