Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-21720

Опубликовано: 27 янв. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
Версия от 3.0.0 (включая) до 11.6.9 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
Версия от 3.0.0 (включая) до 11.6.9 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
Версия от 12.0.0 (включая) до 12.0.8 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
Версия от 12.0.0 (включая) до 12.0.8 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
Версия от 12.1.0 (включая) до 12.1.5 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
Версия от 12.1.0 (включая) до 12.1.5 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:-:*:*:*
Версия от 12.2.0 (включая) до 12.2.3 (исключая)
cpe:2.3:a:grafana:grafana:*:*:*:*:enterprise:*:*:*
Версия от 12.2.0 (включая) до 12.2.3 (исключая)
cpe:2.3:a:grafana:grafana:12.3.0:*:*:*:-:*:*:*
cpe:2.3:a:grafana:grafana:12.3.0:*:*:*:enterprise:*:*:*

EPSS

Процентиль: 5%
0.00018
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
2 месяца назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
redhat
2 месяца назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
debian
2 месяца назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes ...

CVSS3: 7.5
github
2 месяца назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 5%
0.00018
Низкий

7.5 High

CVSS3

Дефекты

CWE-400