Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcrm-48rh-35pj

Опубликовано: 23 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

EPSS

Процентиль: 10%
0.00198
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 5.3
redhat
25 дней назад

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

CVSS3: 5.3
nvd
25 дней назад

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

CVSS3: 5.3
redos
20 дней назад

Уязвимость grafana

EPSS

Процентиль: 10%
0.00198
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-400