Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-21723

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 5.3

Описание

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

A flaw was found in Grafana. A remote attacker with very low privileges, or even anonymous access if enabled, can exploit the alertmanager templates test endpoint by mass-executing templates. This can lead to an Out-Of-Memory (OOM) error, causing the Grafana service to crash and resulting in a Denial of Service (DoS).

Отчет

This Moderate flaw in Grafana allows a remote attacker to trigger a Denial of Service by repeatedly executing alertmanager templates. While requiring low privileges, or anonymous access if enabled, the high attack complexity limits the immediate threat, as it relies on exhausting memory through mass template execution.

Меры по смягчению последствий

If not required, disable anonymous access to prevent unauthenticated exploitation of the Alertmanager templates test endpoint. Refer to Grafana’s official documentation for configuration details. To protect against low-privileged authenticated users triggering this flaw, configure a reverse proxy or WAF to block or strictly rate-limit traffic to /api/alertmanager/grafana/config/api/v1/templates/test.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Fix deferred
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Fix deferred
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph/grafana-rhel10Fix deferred
Red Hat Enterprise Linux 10grafanaFix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 9grafanaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2506342grafana: Grafana: Denial of Service via uncontrolled memory usage in alertmanager templates

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
25 дней назад

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

CVSS3: 5.3
redos
20 дней назад

Уязвимость grafana

CVSS3: 5.3
github
25 дней назад

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a short period causes OOM and crashes the Grafana service. The endpoint requires very low privileges and is exploitable with anonymous access enabled.

5.3 Medium

CVSS3