Описание
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
A flaw was found in Grafana. An unauthenticated attacker can exploit the public dashboard query endpoint by sending arbitrarily large JSON payloads. This vulnerability, caused by a lack of request body size limits, triggers excessive memory allocation, leading to a denial of service through memory exhaustion.
Отчет
This is an Important denial of service vulnerability in Grafana, affecting Red Hat products that include Grafana. Unauthenticated remote attackers can exploit the public dashboard query endpoint by sending large JSON payloads, leading to excessive memory allocation and potential service disruption. The absence of authentication requirements for exploitation increases the risk of widespread impact.
Меры по смягчению последствий
Restrict network access to the Grafana instance to only trusted clients and networks. This can be achieved by configuring firewall rules to limit inbound connections to the Grafana service port. If Grafana is exposed via a reverse proxy, ensure the proxy is configured to limit request body sizes to prevent large payloads from reaching Grafana. A service restart may be required for network configuration changes to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Multicluster Global Hub | multicluster-globalhub/multicluster-globalhub-grafana-rhel9 | Affected | ||
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/acm-grafana-rhel9 | Affected | ||
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Fix deferred | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Fix deferred | ||
| Red Hat Ceph Storage 9 | rhceph/grafana-rhel10 | Fix deferred | ||
| Red Hat Enterprise Linux 10 | grafana | Fixed | RHSA-2026:54178 | 12.08.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | grafana | Fixed | RHSA-2026:67517 | 15.09.2026 |
| Red Hat Enterprise Linux 8 | grafana | Fixed | RHSA-2026:54243 | 12.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attackers to trigger excessive memory allocation by sending arbitrarily large JSON payloads. This can lead to denial of service through memory exhaustion. No valid dashboard access token or authentication is required to exploit this vulnerability.
Grafana: Pre-authentication denial of service in the public dashboard query handler
EPSS
7.5 High
CVSS3