Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42127

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

A flaw was found in Grafana. An unauthenticated attacker can exploit the public dashboard query endpoint by sending arbitrarily large JSON payloads. This vulnerability, caused by a lack of request body size limits, triggers excessive memory allocation, leading to a denial of service through memory exhaustion.

Отчет

This is an Important denial of service vulnerability in Grafana, affecting Red Hat products that include Grafana. Unauthenticated remote attackers can exploit the public dashboard query endpoint by sending large JSON payloads, leading to excessive memory allocation and potential service disruption. The absence of authentication requirements for exploitation increases the risk of widespread impact.

Меры по смягчению последствий

Restrict network access to the Grafana instance to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the Grafana service port. If Grafana is exposed via a reverse proxy, ensure the proxy is configured to limit request body sizes to prevent large payloads from reaching Grafana. A service restart may be required for network configuration changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Multicluster Global Hubmulticluster-globalhub/multicluster-globalhub-grafana-rhel9Affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/acm-grafana-rhel9Affected
Red Hat Ceph Storage 5rhceph/rhceph-5-dashboard-rhel8Fix deferred
Red Hat Ceph Storage 6rhceph/rhceph-6-dashboard-rhel9Fix deferred
Red Hat Ceph Storage 7rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 8rhceph/grafana-rhel9Fix deferred
Red Hat Ceph Storage 9rhceph/grafana-rhel10Fix deferred
Red Hat Enterprise Linux 10grafanaFixedRHSA-2026:5417812.08.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportgrafanaFixedRHSA-2026:6751715.09.2026
Red Hat Enterprise Linux 8grafanaFixedRHSA-2026:5424312.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2491449grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads

EPSS

Процентиль: 37%
0.00432
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
nvd
3 месяца назад

The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.

CVSS3: 7.5
redos
2 месяца назад

Уязвимость grafana

rocky
8 дней назад

Important: grafana security update

CVSS3: 7.5
github
3 месяца назад

Grafana: Pre-authentication denial of service in the public dashboard query handler

EPSS

Процентиль: 37%
0.00432
Низкий

7.5 High

CVSS3