Vulnerability GHSA-3w66-95m3-8jxg
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 22, 2026 at 06:34 PM UTC
Grafana: Pre-authentication denial of service in the public dashboard query handler
v0.0.0-cloud - v6.1.6+incompatible
v0.0.0-cloud - v6.1.6+incompatible
Summary
Grafana: Pre-authentication denial of service in the public dashboard query handler
Details
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 hours ago
Grafana: Pre-authentication denial of service in the public dashboard query handler in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6541
v0.0.1-test - v6.1.6+incompatible GO-2026-6541
Unknown
2 hours ago
Grafana geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6542
v0.0.1-test - v6.1.6+incompatible GO-2026-6542
Unknown
2 hours ago
Grafana Loki datasource plugin's callResource handler contains a path traversal vulnerability. in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6544
v0.0.1-test - v6.1.6+incompatible GO-2026-6544
Unknown
2 hours ago
Grafana: Path traversal in the Tempo and Loki data source plugins in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-6545
v0.0.1-test - v6.1.6+incompatible GO-2026-6545
Unknown
3 months ago
Grafana: Users can generate Service Account tokens after permissions removal in github.com/grafana/grafana
v0.0.1-test - v6.1.6+incompatible GO-2026-5708
v0.0.1-test - v6.1.6+incompatible GO-2026-5708
Impacted packages
Timeline
Published
3 months ago
June 22, 2026 at 06:34 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:10 PM UTC