VYPR
High severity7.5OSV Advisory· Published Jul 10, 2026· Updated Jul 13, 2026

CVE-2026-33382

CVE-2026-33382

Description

Several Grafana API endpoints, some of them unauthenticated, do not limit the size of the request body before processing it. An attacker can send very large payloads that force excessive memory allocation, potentially exhausting memory and causing a denial of service.

Affected products

8

Patches

Vulnerability mechanics

References

1

News mentions

1