Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

fstec логотип

BDU:2026-03572

6 месяцев назад

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260310-73-0036

5 месяцев назад

Уязвимость grafana

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-21720

6 месяцев назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-21720

6 месяцев назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-21720

6 месяцев назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-21720

6 месяцев назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m4rj-q4ph-fr4v

6 месяцев назад

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1037-1

4 месяца назад

Security update for grafana

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:1013-1

4 месяца назад

Security update 5.0.7 for Multi-Linux Manager Client Tools

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20654-1

3 месяца назад

Security update for grafana

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2026-03572

Уязвимость платформы для мониторинга и наблюдения Grafana, связанная с неконтролируемым расходом ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redos логотип
ROS-20260310-73-0036

Уязвимость grafana

CVSS3: 7.5
1%
Низкий
5 месяцев назад
ubuntu логотип
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
nvd логотип
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
debian логотип
CVE-2026-21720

Every uncached /avatar/:hash request spawns a goroutine that refreshes ...

CVSS3: 7.5
1%
Низкий
6 месяцев назад
github логотип
GHSA-m4rj-q4ph-fr4v

Every uncached /avatar/:hash request spawns a goroutine that refreshes the Gravatar image. If the refresh sits in the 10-slot worker queue longer than three seconds, the handler times out and stops listening for the result, so that goroutine blocks forever trying to send on an unbuffered channel. Sustained traffic with random hashes keeps tripping this timeout, so goroutine count grows linearly, eventually exhausting memory and causing Grafana to crash on some systems.

CVSS3: 7.5
1%
Низкий
6 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:1037-1

Security update for grafana

4 месяца назад
suse-cvrf логотип
SUSE-SU-2026:1013-1

Security update 5.0.7 for Multi-Linux Manager Client Tools

4 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20654-1

Security update for grafana

3 месяца назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.