Vulnerability GHSA-3w66-95m3-8jxg

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 22, 2026 at 06:34 PM UTC
Grafana: Pre-authentication denial of service in the public dashboard query handler
v0.0.0-cloud - v6.1.6+incompatible
v0.0.0-cloud - v6.1.6+incompatible

Summary

Grafana: Pre-authentication denial of service in the public dashboard query handler

Details

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

Timeline

Published
3 months ago
June 22, 2026 at 06:34 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:10 PM UTC