The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 14 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Grafana
Grafana grafana |
|
| Vendors & Products |
Grafana
Grafana grafana |
Wed, 13 May 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming request body, potentially leading to out-of-memory conditions. An authenticated user with access to the Grafana Live API can trigger this issue. | |
| Title | Grafana Live push endpoint allows unbounded memory allocation leading to OOM | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GRAFANA
Published:
Updated: 2026-05-13T19:35:07.723Z
Reserved: 2026-02-27T07:16:12.218Z
Link: CVE-2026-28376
No data.
Status : Awaiting Analysis
Published: 2026-05-13T20:16:19.760
Modified: 2026-05-14T16:21:02.930
Link: CVE-2026-28376
No data.
OpenCVE Enrichment
Updated: 2026-05-14T14:00:19Z
Weaknesses
No weakness.